PT-2026-27253 · WordPress · Wp Job Portal

Leonid Semenenko

·

Published

2026-03-23

·

Updated

2026-03-24

·

CVE-2026-4306

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Job Portal plugin for WordPress versions prior to 2.4.9
Description The WP Job Portal plugin for WordPress is susceptible to SQL Injection due to inadequate input sanitization and insufficient SQL query preparation. Specifically, the radius parameter is not properly escaped, allowing unauthenticated attackers to inject additional SQL queries into existing database queries. This could enable attackers to extract sensitive information from the database.
Recommendations Update the WP Job Portal plugin to version 2.4.9 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-4306

Affected Products

Wp Job Portal