# WP Job Manager <= 2.4.7 - Authenticated (Contributor+) Sensitive Information Exposure via [jobs] Shortcode 'post_status' Attribute

- **ID:** WPSEC-2026-0611
- **Plugin:** WP Job Manager (`wp-job-manager`), https://wordpress.org/plugins/wp-job-manager/
- **Affected versions:** from 1.27.0 before 2.4.8
- **Fixed in:** 2.4.8 (Update to 2.4.8 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-863
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-job-manager
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0611/

## Description

The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure via the [jobs] shortcode in versions 1.27.0 up to, and including, 2.4.7. The shortcode honoured any requested 'post_status' attribute value without checking the viewer's capabilities. This makes it possible for authenticated attackers, with Contributor-level access and above, to place the shortcode in a draft post and preview it, listing other users' non-public job listings, such as drafts, pending, private and unpaid submissions, with their titles, company names, logos, locations and job types.

## References

- https://wpsec.com/vuln/WPSEC-2026-0611/
- https://plugins.svn.wordpress.org/wp-job-manager/tags/2.4.8/
- https://wordpress.org/plugins/wp-job-manager/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0611/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
