Vulnerabilities / WP Job Manager / WPSEC-2026-0612
WP Job Manager <= 2.4.7 - Authenticated (Subscriber+) Sensitive Information Exposure via Edit Job Form Attachment Fields
Medium 4.3
CWE-200Fixed in 2.4.8
- ID
- WPSEC-2026-0612
- Plugin
- WP Job Manager (wp-job-manager)
- Affected
- from 1.24.0 before 2.4.8
- Remediation
- Update to 2.4.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- WP Job Manager on WPSec AttackSurface
- Fix released
- Published
Description
The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure via the frontend edit job form in versions 1.24.0 up to, and including, 2.4.7. Posted attachment field values were not scrubbed before the form was re-rendered after a validation failure. This makes it possible for authenticated attackers, with Subscriber-level access and above, who can edit one of their own job listings, to submit the ID of an image attachment they are not permitted to use and have its URL echoed back, which can disclose media attached to non-public content.
References
- https://wpsec.com/vuln/WPSEC-2026-0612/
- https://plugins.svn.wordpress.org/wp-job-manager/tags/2.4.8/
- https://wordpress.org/plugins/wp-job-manager/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS