Executive brief
The WP Job Portal plugin for WordPress, which provides job board and recruitment functionality, contains a critical security flaw. An attacker can use this vulnerability to interact directly with the website's database without needing a username or password. This could lead to the theft of sensitive information, such as user data or job seeker details, and potentially disrupt site operations.
Technical details
A blind SQL injection vulnerability exists in the Ahmad WP Job Portal plugin for WordPress due to improper neutralization of special elements used in an SQL command. The flaw allows an unauthenticated remote attacker to send specially crafted requests to the application to execute arbitrary SQL queries against the backend database. Because it is a blind SQL injection, the attacker can infer data by observing differences in application responses or timing. This issue affects all versions up to and including 2.5.1; it was addressed in version 2.5.2.
Affected products
- Ahmad WP Job Portal <= 2.5.1
Timeline
- 2026-04-23: other: Vulnerability reported by researcher hhhai
- 2026-05-23: advisory: Patchstack published initial advisory
- 2026-06-02: disclosed: CVE published to NVD dataset
- 2026-05-23: patched: Version 2.5.2 released to address the vulnerability