
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24941 is a Missing Authorization (Broken Access Control) vulnerability in the WP Job Portal WordPress plugin that allows unauthenticated remote attackers to exploit incorrectly configured access control security levels. It affects WP Job Portal versions up to and including 2.4.4, with version 2.4.5 containing the fix. The vulnerability was reported on October 29, 2025, and published on February 3, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing certain privileged actions. An unauthenticated remote attacker can send crafted network requests to trigger functionality that should be restricted to higher-privileged users, exploiting incorrectly configured access control levels. No prior authentication, user interaction, or special conditions are required for exploitation (Patchstack).
Successful exploitation results in a high confidentiality impact with no integrity or availability impact, meaning attackers can access sensitive data exposed by the plugin without being able to modify or disrupt it. The vulnerability is network-exploitable with no authentication required, making it suitable for mass-exploit campaigns targeting WordPress sites running the affected plugin. The scope is limited to the affected system, but unauthorized access to job portal data — potentially including applicant personal information or employer details — represents a significant data exposure risk (Patchstack).
No public proof-of-concept exploit code has been identified at this time, though Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. The EPSS score is approximately 0.032%, indicating a relatively low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no specific threat actor attribution has been reported (Patchstack).
/wp-admin/admin-ajax.php or plugin-specific REST routes) from unknown or automated IP addresses.The vendor has released WP Job Portal version 2.4.5, which patches this vulnerability. Site administrators should update the plugin to version 2.4.5 or later immediately. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated, and auto-update for vulnerable plugins can be enabled via the Patchstack dashboard (Patchstack).
Patchstack, which coordinated the disclosure after researcher benzdeus reported the vulnerability on October 29, 2025, classified it as high priority and noted its potential for mass exploitation campaigns. The vulnerability was also noted on Bluesky by The Hacker Wire and aggregated by several CVE tracking services shortly after publication (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."