{
 "id": "WPSEC-2026-0612",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0612/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0612/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0612/index.md",
 "title": "WP Job Manager <= 2.4.7 - Authenticated (Subscriber+) Sensitive Information Exposure via Edit Job Form Attachment Fields",
 "description": "The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure via the frontend edit job form in versions 1.24.0 up to, and including, 2.4.7. Posted attachment field values were not scrubbed before the form was re-rendered after a validation failure. This makes it possible for authenticated attackers, with Subscriber-level access and above, who can edit one of their own job listings, to submit the ID of an image attachment they are not permitted to use and have its URL echoed back, which can disclose media attached to non-public content.",
 "plugin": {
  "slug": "wp-job-manager",
  "name": "WP Job Manager",
  "full_name": "WP Job Manager",
  "wordpress_org": "https://wordpress.org/plugins/wp-job-manager/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-job-manager/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-job-manager"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.24.0",
    "from_inclusive": true,
    "to": "2.4.8",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.24.0 before 2.4.8"
  ]
 },
 "introduced_in": "1.24.0",
 "fixed_in": "2.4.8",
 "remediation": "Update to 2.4.8 or later.",
 "fix_released": "2026-10-07T04:39:26+00:00",
 "published": "2026-10-08T04:46:19+00:00",
 "updated": "2026-10-07T11:22:47.126991+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0612/",
  "https://plugins.svn.wordpress.org/wp-job-manager/tags/2.4.8/",
  "https://wordpress.org/plugins/wp-job-manager/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-job-manager",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-07"
 }
}