Junglewise Threat Intelligence

CVE-2026-42685: Ahmad WP Job Portal Reflected XSS

CVE-2026-42685 · Severity: high · CVSS 7.1 · Published 2026-06-02

Technologies: Ahmad WP Job Portal. Vendors: Ahmad.

Executive brief

The WP Job Portal plugin for WordPress, which provides job board functionality, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. An attacker can trick a user into clicking a specially crafted link, leading to unauthorized actions, data theft, or redirection to malicious websites. This could compromise the accounts of site visitors or administrators and damage the website's reputation.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Ahmad WP Job Portal plugin for WordPress (versions <= 2.5.1) due to improper neutralization of user-supplied input during web page generation. The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's browser session. Exploitation requires a victim to interact with a malicious link or crafted page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized administrative actions, or the delivery of further browser-based exploits. The issue is resolved in version 2.5.2.

Affected products

  • Ahmad WP Job Portal <= 2.5.1

Timeline

  • 2026-04-23: other: Reported by hhhai
  • 2026-05-23: advisory: Patchstack advisory published
  • 2026-06-02: disclosed: CVE published to NVD

References

Related threats