Vulnerabilities / WP Job Manager / WPSEC-2026-0612

WP Job Manager <= 2.4.7 - Authenticated (Subscriber+) Sensitive Information Exposure via Edit Job Form Attachment Fields

Medium 4.3 CWE-200Fixed in 2.4.8
ID
WPSEC-2026-0612
Plugin
WP Job Manager (wp-job-manager)
Affected
from 1.24.0 before 2.4.8
Remediation
Update to 2.4.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
WP Job Manager on WPSec AttackSurface
Fix released
Published

Description

The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure via the frontend edit job form in versions 1.24.0 up to, and including, 2.4.7. Posted attachment field values were not scrubbed before the form was re-rendered after a validation failure. This makes it possible for authenticated attackers, with Subscriber-level access and above, who can edit one of their own job listings, to submit the ID of an image attachment they are not permitted to use and have its URL echoed back, which can disclose media attached to non-public content.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0