Junglewise Threat Intelligence

CVE-2026-12395: WP Job Portal SQL injection in Applied Resumes ta parameter

CVE-2026-12395 · Severity: info · CVSS 7.7 · Published 2026-07-16

Technologies: WP Job Portal.

Executive brief

WP Job Portal is a WordPress plugin used to manage job listings and applications. A security flaw allows registered users, such as job seekers, to execute unauthorized database commands. This could lead to the theft of sensitive user data, modification of site content, or full compromise of the website's database.

Technical details

A SQL injection vulnerability exists in the WP Job Portal plugin for WordPress due to insufficient sanitization and escaping of the 'ta' parameter within the Applied Resumes functionality. The flaw allows authenticated users with subscriber-level privileges (which are often self-registerable) to inject arbitrary SQL commands into backend queries. This can result in unauthorized data extraction, modification, or deletion from the WordPress database. The issue is fixed in version 2.5.5.

Affected products

  • WP Job Portal WP Job Portal < 2.5.5

Timeline

  • 2026-06-25: disclosed: Publicly published by WPScan
  • 2026-07-16: advisory: NVD publication date
  • 2026-07-16: patched: Fixed in version 2.5.5

References