What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.1.
Explanation of Vulnerability in Simple Terms
02Summary
JobWP exposes sensitive information without proper access controls. An unauthenticated attacker can read data that should be restricted, such as job listings, applicant details, or other plugin data. This affects all versions up to 2.1. Update immediately to a version newer than 2.1.
What an attacker can do
03Attacker Capabilities
Read sensitive job board data without logging in, including job listings and applicant information.
Potential impact on your site
04Site Impact
Applicant personal information, job details, and internal recruitment data are exposed to anyone on the internet.
Conditions required to exploit
05Prerequisites
None. The attacker needs only network access; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 21, 2023
CVE published
April 28, 2026
Record updated