What the vulnerability does
01Description
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
Explanation of Vulnerability in Simple Terms
WP Job Portal versions up to 2.5.9 contain an authorization bypass vulnerability in user-controlled key handling. A logged-in attacker can modify requests to alter data they should not have access to. The vulnerability requires low privileges and no user interaction. Update to a version newer than 2.5.9 to remediate.
What an attacker can do
Modify job listings or portal data belonging to other users without proper authorization.
Potential impact on your site
Unauthorized changes to job postings and portal content; data integrity compromised across the job board.
Conditions required to exploit
Attacker must have a valid user account with low-level access to the plugin.
Key dates
External resources
Related vulnerabilities