WordPress · Ahmad Wp Job Portal · CVE-2026-42685
**Name of the Vulnerable Software and Affected Versions**
Ahmad WP Job Portal versions prior to 2.5.1
**Description**
Improper neutralization of input during web page generation allows Reflected Cross-Site Scripting (XSS), a flaw where an application includes untrusted data in a web page without proper validation or escaping, enabling attackers to execute malicious scripts in the victim's browser.
**Recommendations**
Update to a version later than 2.5.1.