CVE-2026-24379: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24379 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the WP Job Portal WordPress plugin. It affects all versions up to and including 2.4.3, and was patched in version 2.4.4. The vulnerability was reported by Nabil Irawan on December 25, 2025, and published on January 22–24, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) per Feedly/NVD data, while Patchstack rates it 4.3 (Low) (Patchstack).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), which maps to the OWASP Top 10 category A1: Broken Access Control. The plugin fails to properly validate server-side authorization when processing user-supplied object identifiers, allowing an authenticated user (with at minimum Subscriber-level access) to reference and interact with objects belonging to other users or restricted areas. This is a classic IDOR pattern where predictable or enumerable keys in requests are not verified against the requesting user's permissions (Patchstack).

Impact

Successful exploitation could allow an authenticated attacker (Subscriber-level or higher) to bypass access controls and interact with job portal data or plugin functionality they are not authorized to access. This may include unauthorized access to sensitive job application data, candidate information, or plugin settings, as well as potential modification of records belonging to other users. Confidentiality and integrity of job portal data are the primary concerns, with no direct availability impact indicated by the CVSS vector (Patchstack).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is very low at approximately 0.017%, reflecting a low probability of near-term exploitation. The vulnerability requires at least a low-privileged authenticated account (Subscriber level), which raises the bar slightly compared to unauthenticated flaws. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running WP Job Portal version 2.4.3 or earlier using tools like WPScan or by inspecting plugin metadata in publicly accessible readme files.
  2. Obtain low-privileged access: Register or obtain a Subscriber-level account on the target WordPress site, as the vulnerability requires at minimum this level of authentication.
  3. Identify object references: Browse the job portal functionality (e.g., job applications, candidate profiles, employer records) and capture HTTP requests containing object identifiers (IDs) in parameters.
  4. Manipulate object keys: Modify the user-controlled object identifier in the request (e.g., change an application ID or user ID parameter) to reference records belonging to other users or restricted resources.
  5. Access unauthorized data: Submit the manipulated request and observe whether the server returns data or performs actions associated with the referenced object, bypassing the intended access control checks (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated requests (with valid session cookies) to WP Job Portal endpoints with sequentially enumerated or out-of-range object ID parameters (e.g., ?job_id=, ?application_id=, ?candidate_id= values that differ from those assigned to the authenticated user).
  • Logs: Repeated access to job portal admin or data endpoints from a single low-privileged user account in a short time window, suggesting automated enumeration.
  • Network: Unusual patterns of HTTP GET or POST requests to WP Job Portal plugin URLs with varying numeric ID parameters from the same source IP.

Mitigation and workarounds

The vendor has released version 2.4.4 of WP Job Portal, which patches this vulnerability. All site administrators running version 2.4.3 or earlier should update immediately via the WordPress plugin dashboard. As a temporary workaround if immediate update is not possible, restrict user registration or limit Subscriber-level access to job portal functionality, and consider using a web application firewall (WAF) rule to flag anomalous object reference patterns. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically (Patchstack).

Community reactions

Patchstack, which coordinated the disclosure through its Active VDP program, classified the vulnerability as low priority with low severity impact and noted it is unlikely to be exploited at scale. The vulnerability was noted in automated CVE tracking feeds and aggregators shortly after publication, with no significant independent researcher commentary or media coverage identified beyond standard database entries.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management