WP Job Manager <= 2.4.7 - Unauthenticated Sensitive Information Exposure via Listing Archives, Term Feeds, Sitemaps and REST API
- ID
- WPSEC-2026-0613
- Plugin
- WP Job Manager (wp-job-manager)
- Affected
- from 1.37.0 before 2.4.8
- Remediation
- Update to 2.4.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-284
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- WP Job Manager on WPSec AttackSurface
- Fix released
- Published
Description
The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 1.37.0 up to, and including, 2.4.7. The plugin's 'Browse Job Capability' and 'View Job Capability' restrictions were not enforced on several listing surfaces: front-end job listing archive queries, job category and job type term archives and their RSS feeds, and site sitemaps. REST API responses for restricted listings also kept the guid field, which can contain the listing's permalink slug. This makes it possible for unauthenticated attackers, on sites that restrict job listings to specific roles with these settings, to read the titles and descriptions of published job listings and to enumerate their URLs.
References
- https://wpsec.com/vuln/WPSEC-2026-0613/
- https://plugins.svn.wordpress.org/wp-job-manager/tags/2.4.8/
- https://wordpress.org/plugins/wp-job-manager/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS