{
 "id": "WPSEC-2026-0613",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0613/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0613/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0613/index.md",
 "title": "WP Job Manager <= 2.4.7 - Unauthenticated Sensitive Information Exposure via Listing Archives, Term Feeds, Sitemaps and REST API",
 "description": "The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 1.37.0 up to, and including, 2.4.7. The plugin's 'Browse Job Capability' and 'View Job Capability' restrictions were not enforced on several listing surfaces: front-end job listing archive queries, job category and job type term archives and their RSS feeds, and site sitemaps. REST API responses for restricted listings also kept the guid field, which can contain the listing's permalink slug. This makes it possible for unauthenticated attackers, on sites that restrict job listings to specific roles with these settings, to read the titles and descriptions of published job listings and to enumerate their URLs.",
 "plugin": {
  "slug": "wp-job-manager",
  "name": "WP Job Manager",
  "full_name": "WP Job Manager",
  "wordpress_org": "https://wordpress.org/plugins/wp-job-manager/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-job-manager/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-job-manager"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-284"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.37.0",
    "from_inclusive": true,
    "to": "2.4.8",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.37.0 before 2.4.8"
  ]
 },
 "introduced_in": "1.37.0",
 "fixed_in": "2.4.8",
 "remediation": "Update to 2.4.8 or later.",
 "fix_released": "2026-10-07T04:39:26+00:00",
 "published": "2026-10-08T04:46:19+00:00",
 "updated": "2026-10-07T11:22:47.126991+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0613/",
  "https://plugins.svn.wordpress.org/wp-job-manager/tags/2.4.8/",
  "https://wordpress.org/plugins/wp-job-manager/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-job-manager",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-07"
 }
}