Junglewise Threat Intelligence

CVE-2026-57653: wpjobportal WP Job Portal SQL injection

CVE-2026-57653 · Severity: high · CVSS 8.5 · Published 2026-06-26

Technologies: Wpjobportal WP Job Portal.

Executive brief

WP Job Portal is a WordPress plugin used to create and manage job boards. A security vulnerability in versions 2.5.2 and earlier allows users with 'Contributor' level access to perform unauthorized database queries. This could lead to the theft of sensitive information from the website's database or disruption of site operations.

Technical details

A SQL injection vulnerability exists in the WP Job Portal plugin for WordPress (versions <= 2.5.2) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows an authenticated attacker with Contributor-level privileges to execute arbitrary SQL queries against the backend database. This is achieved via a network-based attack vector with low complexity. Successful exploitation can lead to high confidentiality impact and limited availability impact. The issue is resolved in version 2.5.3.

Affected products

  • wpjobportal WP Job Portal <= 2.5.2

Timeline

  • 2026-05-11: disclosed: Reported by hhhai
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Patch released in version 2.5.3

References