
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24379 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the WP Job Portal WordPress plugin. It affects all versions up to and including 2.4.3, and was patched in version 2.4.4. The vulnerability was reported by Nabil Irawan on December 25, 2025, and published on January 22–24, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) per Feedly/NVD data, while Patchstack rates it 4.3 (Low) (Patchstack).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), which maps to the OWASP Top 10 category A1: Broken Access Control. The plugin fails to properly validate server-side authorization when processing user-supplied object identifiers, allowing an authenticated user (with at minimum Subscriber-level access) to reference and interact with objects belonging to other users or restricted areas. This is a classic IDOR pattern where predictable or enumerable keys in requests are not verified against the requesting user's permissions (Patchstack).
Successful exploitation could allow an authenticated attacker (Subscriber-level or higher) to bypass access controls and interact with job portal data or plugin functionality they are not authorized to access. This may include unauthorized access to sensitive job application data, candidate information, or plugin settings, as well as potential modification of records belonging to other users. Confidentiality and integrity of job portal data are the primary concerns, with no direct availability impact indicated by the CVSS vector (Patchstack).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is very low at approximately 0.017%, reflecting a low probability of near-term exploitation. The vulnerability requires at least a low-privileged authenticated account (Subscriber level), which raises the bar slightly compared to unauthenticated flaws. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
?job_id=, ?application_id=, ?candidate_id= values that differ from those assigned to the authenticated user).The vendor has released version 2.4.4 of WP Job Portal, which patches this vulnerability. All site administrators running version 2.4.3 or earlier should update immediately via the WordPress plugin dashboard. As a temporary workaround if immediate update is not possible, restrict user registration or limit Subscriber-level access to job portal functionality, and consider using a web application firewall (WAF) rule to flag anomalous object reference patterns. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically (Patchstack).
Patchstack, which coordinated the disclosure through its Active VDP program, classified the vulnerability as low priority with low severity impact and noted it is unlikely to be exploited at scale. The vulnerability was noted in automated CVE tracking feeds and aggregators shortly after publication, with no significant independent researcher commentary or media coverage identified beyond standard database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."