WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–40 of 40 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.5.9 Fixed in 2.6.0 CVE-2026-81299 Patchstack
8.5 High WP Job Portal Plugin wp-job-portal SQL Injection ≤ 2.5.6 Fixed in 2.5.7 CVE-2026-65569 Patchstack
6.5 Medium WP Job Portal Plugin wp-job-portal SQL Injection Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter < 2.5.5 Fixed in 2.5.5 CVE-2026-12395 WPScan
4.3 Medium WP Job Portal Plugin wp-job-portal Information Disclosure Subscriber+ Employer Email Disclosure via IDOR < 2.5.5 Fixed in 2.5.5 CVE-2026-12397 WPScan
5.4 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Subscriber+ Arbitrary Job Approval, Featuring and Rejection < 2.5.5 Fixed in 2.5.5 CVE-2026-12396 WPScan
8.5 High WP Job Portal Plugin wp-job-portal SQL Injection ≤ 2.5.2 Fixed in 2.5.3 CVE-2026-57653 Patchstack
6.5 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.5.2 Fixed in 2.5.3 CVE-2026-48880 Patchstack
7.1 High WP Job Portal Plugin wp-job-portal Cross-Site Scripting No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-42685 Patchstack
9.3 Critical WP Job Portal Plugin wp-job-portal SQL Injection No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-42684 Patchstack
8.8 High WP Job Portal Plugin wp-job-portal Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field ≤ 2.4.9 CVE-2026-4758 Wordfence
7.5 High WP Job Portal Plugin wp-job-portal SQL Injection Unauthenticated SQL Injection via 'radius' Parameter No login needed ≤ 2.4.8 CVE-2026-4306 Wordfence
7.5 High WP Job Portal Plugin wp-job-portal Broken Access Control No login needed ≤ 2.4.4 Fixed in 2.4.5 CVE-2026-24941 Patchstack
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.4.3 Fixed in 2.4.4 CVE-2026-24379 Patchstack
4.4 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Job Description Field ≤ 2.3.9 CVE-2025-14467 Wordfence
6.5 Medium WP Job Portal Plugin wp-job-portal Path Traversal Authenticated (Subscriber+) Arbitrary File Read ≤ 2.4.0 CVE-2025-14293 Wordfence
9.3 Critical WP Job Portal Plugin wp-job-portal SQL Injection No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-48274 Patchstack
8.1 High WP Job Portal Plugin wp-job-portal Local File Inclusion No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-47438 Patchstack
7.5 High WP Job Portal Plugin wp-job-portal Path Traversal Arbitrary File Download No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-48273 Patchstack
5.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-48272 Patchstack
7.5 High WP Job Portal Plugin wp-job-portal Local File Inclusion ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-26935 Patchstack
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) User Photo Disconnection ≤ 2.2.8 CVE-2024-13873 Wordfence
5.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object Reference to Unauthenticated Company Logo Deletion No login needed ≤ 2.2.6 CVE-2024-13428 Wordfence
5.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Resume Download No login needed ≤ 2.2.6 CVE-2024-13372 Wordfence
5.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Missing Authorization to Unauthenticated Arbitrary Email Sending No login needed ≤ 2.2.6 CVE-2024-13371 Wordfence
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Job Deletion ≤ 2.2.6 CVE-2024-13429 Wordfence
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Company Deletion ≤ 2.2.6 CVE-2024-13425 Wordfence
4.3 Medium WP Job Portal – A Complete Recruitment System for Company or Job Board website Plugin wp-job-portal Broken Access Control A Complete Recruitment System for Company or Job Board website <= 2.2.5- Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 2.2.5 CVE-2024-12131 Wordfence
5.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Missing Authorization to Unauthenticated Arbitrary Resume Download No login needed ≤ 2.2.2 CVE-2024-11712 Wordfence
7.5 High WP Job Portal Plugin wp-job-portal SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.2.1 CVE-2024-11711 Wordfence
4.9 Medium WP Job Portal Plugin wp-job-portal SQL Injection Authenticated (Admin+) SQL Injection ≤ 2.2.2 CVE-2024-11710 Wordfence
4.9 Medium WP Job Portal Plugin wp-job-portal SQL Injection Authenticated (Admin+) SQL Injection via getFieldsForVisibleCombobox() ≤ 2.2.2 CVE-2024-11714 Wordfence
4.9 Medium WP Job Portal Plugin wp-job-portal SQL Injection Authenticated (Admin+) SQL Injection via wpjobportal_deactivate() ≤ 2.2.2 CVE-2024-11713 Wordfence
4.8 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Missing Authorization to Limited Privilege Escalation No login needed ≤ 2.2.2 CVE-2024-11715 Wordfence
6.5 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-52389 Patchstack
9.8 Critical WP Job Portal Plugin wp-job-portal Broken Access Control Missing Authorization to Unauthenticated Local File Inclusion, Arbitrary Settings Update, and User Creation No login needed ≤ 2.1.6 CVE-2024-7950 Wordfence
5.4 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.1.8 Fixed in 2.1.9 CVE-2024-43266 Patchstack
5.9 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35759 Patchstack
5.9 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35760 Patchstack
5.4 Medium WP Job Portal – A Complete Job Board Plugin wp-job-portal Broken Access Control WordPress WP Job Portal Plugin <= 2.0.1 is vulnerable to Broken Access Control No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2022-41786 Patchstack
4.3 Medium WP Job Portal – A Complete Job Board Plugin wp-job-portal Cross-Site Request Forgery WordPress WP Job Portal Plugin <= 2.0.6 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2023-52184 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only