CVE-2026-4758 identifies a high-severity arbitrary file deletion vulnerability in the WP Job Portal plugin for WordPress, affecting all versions up to and including 2.4.9. This flaw (CVSS 8.8) stems from insufficient file path validation, allowing authenticated attackers with Subscriber-level privileges to delete arbitrary files on the server. Such deletion can lead to critical impacts, including remote code execution if sensitive files like wp-config.php are targeted. Currently, there is no evidence of active exploitation, nor are public exploit modules available in common repositories like Metasploit or ExploitDB, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wpjobportal | WP Job Portal – AI-Powered Recruitment System For Company Or Job Board Website | >= 0, <= 2.4.9CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.