Junglewise Threat Intelligence

CVE-2026-48880: WP Job Portal Cross-Site Scripting in WordPress plugin

CVE-2026-48880 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: WP Job Portal.

Executive brief

WP Job Portal is a WordPress plugin used to create and manage job boards. A security vulnerability allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. If an administrator or another visitor views the affected page, these scripts could lead to unauthorized actions, website defacement, or the theft of sensitive session information.

Technical details

The WP Job Portal plugin for WordPress (versions 2.5.2 and earlier) contains a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input. An attacker with Subscriber-level privileges can inject malicious HTML or JavaScript payloads that are subsequently executed in the browser of any user who views the compromised content. This is a stored XSS vulnerability that requires a victim (typically an administrator) to interact with the affected page. The issue is resolved in version 2.5.3.

Affected products

  • WP Job Portal WP Job Portal <= 2.5.2

Timeline

  • 2026-05-07: other: Reported by researcher Baikuya
  • 2026-06-02: patched: Version 2.5.3 released
  • 2026-06-15: disclosed: NVD publication date

References