Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpjobportal

First CVE: Jun 22, 2023Active for: 3 yearsTotal CVEs: 31
34.8
VTI Score
Medium

WPJobPortal's vulnerability footprint is concentrated in a single WordPress plugin product that, despite modest disclosure volume, ranks prominently in the landscape and presents a notable attack surface for WordPress deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through a consistent pattern of access-control and input-handling flaws, including authorization bypasses, missing authorization checks, SQL injection, cross-site scripting, and path traversal. The plugin's tight integration with WordPress and its role in job-posting functionality create meaningful exposure for sites relying on it, particularly when coupled with the authorization and injection weaknesses that characterize its disclosure history. Defenders should treat updates for this plugin as a patching priority and consider the underlying access-control and input-validation patterns as persistent structural risks requiring attention across plugin versions. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
7.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpjobportal over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 22, 2023
3 years ago
Most Recent CVE
Jun 26, 2026
31 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-4490CRITICAL
The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticat
Sep 25, 20239.840NOYES
CVE-2026-24379CRITICAL
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.Th
Jan 22, 20269.132NONO
CVE-2026-57653HIGH
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
Jun 26, 20268.531NONO
CVE-2024-7950CRITICAL
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary Settings Update, and User C
Sep 4, 20249.829NONO
CVE-2024-11715CRITICAL
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th
Dec 14, 20249.827NONO
CVE-2022-41786CRITICAL
Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.1.
Jan 17, 20249.827NONO
CVE-2025-47438CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local Fi
May 23, 20259.825NONO
CVE-2024-43266HIGH
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue affects WP Job Portal: from n/a through <= 2.1.8.
Aug 18, 20248.825NONO
CVE-2026-24941HIGH
Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Por
Feb 20, 20267.524NONO
CVE-2025-48274HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Blind SQL Injection.This issue
Jun 17, 20257.524NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
55%
26%
19%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None26 (83.9%)
Unknown0 (0.0%)
Required5 (16.1%)
Privileges Required
Low10 (32.3%)
High5 (16.1%)
None16 (51.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.2% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpjobportal.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpjobportal — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpjobportal's Products

View all 3 CNAs →

Top CWEs