Executive brief
WP Job Portal is a WordPress plugin used to create and manage job boards. A security vulnerability allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. If an administrator or another visitor views the affected page, these scripts could lead to unauthorized actions, website defacement, or the theft of sensitive session information.
Technical details
The WP Job Portal plugin for WordPress (versions 2.5.2 and earlier) contains a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input. An attacker with Subscriber-level privileges can inject malicious HTML or JavaScript payloads that are subsequently executed in the browser of any user who views the compromised content. This is a stored XSS vulnerability that requires a victim (typically an administrator) to interact with the affected page. The issue is resolved in version 2.5.3.
Affected products
- WP Job Portal WP Job Portal <= 2.5.2
Timeline
- 2026-05-07: other: Reported by researcher Baikuya
- 2026-06-02: patched: Version 2.5.3 released
- 2026-06-15: disclosed: NVD publication date