What the vulnerability does
01Description
Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal: from n/a through <= 2.2.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal: from n/a through <= 2.2.8.
Explanation of Vulnerability in Simple Terms
WP Job Portal versions 2.2.8 and earlier contain a vulnerability that allows authenticated users with low privileges to read sensitive data, modify site content, or disrupt service. The vulnerability requires network access and high attack complexity. Site administrators should update to a version newer than 2.2.8 as soon as possible.
What an attacker can do
Read sensitive data, modify content, or disrupt the site's availability.
Potential impact on your site
Authenticated users can access confidential information, alter job postings or site data, or cause service disruptions.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities