# WP Job Manager <= 2.4.7 - Authenticated (Subscriber+) Sensitive Information Exposure via Edit Job Form Attachment Fields

- **ID:** WPSEC-2026-0612
- **Plugin:** WP Job Manager (`wp-job-manager`), https://wordpress.org/plugins/wp-job-manager/
- **Affected versions:** from 1.24.0 before 2.4.8
- **Fixed in:** 2.4.8 (Update to 2.4.8 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-job-manager
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0612/

## Description

The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure via the frontend edit job form in versions 1.24.0 up to, and including, 2.4.7. Posted attachment field values were not scrubbed before the form was re-rendered after a validation failure. This makes it possible for authenticated attackers, with Subscriber-level access and above, who can edit one of their own job listings, to submit the ID of an image attachment they are not permitted to use and have its URL echoed back, which can disclose media attached to non-public content.

## References

- https://wpsec.com/vuln/WPSEC-2026-0612/
- https://plugins.svn.wordpress.org/wp-job-manager/tags/2.4.8/
- https://wordpress.org/plugins/wp-job-manager/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0612/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
