# WP Job Manager <= 2.4.7 - Unauthenticated Sensitive Information Exposure via Listing Archives, Term Feeds, Sitemaps and REST API

- **ID:** WPSEC-2026-0613
- **Plugin:** WP Job Manager (`wp-job-manager`), https://wordpress.org/plugins/wp-job-manager/
- **Affected versions:** from 1.37.0 before 2.4.8
- **Fixed in:** 2.4.8 (Update to 2.4.8 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-284
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-job-manager
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0613/

## Description

The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 1.37.0 up to, and including, 2.4.7. The plugin's 'Browse Job Capability' and 'View Job Capability' restrictions were not enforced on several listing surfaces: front-end job listing archive queries, job category and job type term archives and their RSS feeds, and site sitemaps. REST API responses for restricted listings also kept the guid field, which can contain the listing's permalink slug. This makes it possible for unauthenticated attackers, on sites that restrict job listings to specific roles with these settings, to read the titles and descriptions of published job listings and to enumerate their URLs.

## References

- https://wpsec.com/vuln/WPSEC-2026-0613/
- https://plugins.svn.wordpress.org/wp-job-manager/tags/2.4.8/
- https://wordpress.org/plugins/wp-job-manager/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0613/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
