PT-2026-28149 · WordPress · Wp Job Portal+1

·

CVE-2026-4758

·

Publicado

2026-03-25

·

Atualizado

2026-03-26

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Job Portal versions prior to 2.4.9
Description The WP Job Portal plugin for WordPress is susceptible to arbitrary file deletion. This is due to inadequate file path validation within the WPJOBPORTALcustomfields::removeFileCustom function. Authenticated attackers with Subscriber-level access or higher can delete arbitrary files on the server. Deletion of specific files, such as wp-config.php, could lead to remote code execution. The removeFileCustom function is the point of failure.
Recommendations Update WP Job Portal to a version later than 2.4.9.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4758

Produtos afetados

Wp Job Portal
Wordpress