Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-24941
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24941 is a Missing Authorization (Broken Access Control) vulnerability in the WP Job Portal WordPress plugin that allows unauthenticated remote attackers to exploit incorrectly configured access control security levels. It affects WP Job Portal versions up to and including 2.4.4, with version 2.4.5 containing the fix. The vulnerability was reported on October 29, 2025, and published on February 3, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing certain privileged actions. An unauthenticated remote attacker can send crafted network requests to trigger functionality that should be restricted to higher-privileged users, exploiting incorrectly configured access control levels. No prior authentication, user interaction, or special conditions are required for exploitation (Patchstack).

Impact

Successful exploitation results in a high confidentiality impact with no integrity or availability impact, meaning attackers can access sensitive data exposed by the plugin without being able to modify or disrupt it. The vulnerability is network-exploitable with no authentication required, making it suitable for mass-exploit campaigns targeting WordPress sites running the affected plugin. The scope is limited to the affected system, but unauthorized access to job portal data — potentially including applicant personal information or employer details — represents a significant data exposure risk (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified at this time, though Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. The EPSS score is approximately 0.032%, indicating a relatively low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no specific threat actor attribution has been reported (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Job Portal plugin version 2.4.4 or earlier using tools like WPScan, Shodan, or Google dorks targeting plugin-specific paths.
  2. Identify unprotected endpoints: Enumerate plugin-specific REST API routes or admin-ajax actions that lack proper authorization checks, which are accessible without authentication.
  3. Craft malicious request: Send a crafted HTTP GET or POST request to the vulnerable endpoint, bypassing the missing authorization check to invoke a privileged function.
  4. Extract sensitive data: Retrieve confidential information exposed by the plugin (e.g., applicant data, employer details, or internal job portal records) from the server response (Patchstack).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to WP Job Portal plugin endpoints (e.g., paths under /wp-admin/admin-ajax.php or plugin-specific REST routes) from unknown or automated IP addresses.
  • Logs: WordPress access logs showing repeated requests to plugin-specific actions without session cookies or authentication tokens; high-volume requests from a single IP targeting plugin endpoints.
  • File System: No file-system artifacts are expected for this read-only access control bypass, but monitor for any unexpected file creation in the WordPress uploads or plugin directories following exploitation.

Mitigation and workarounds

The vendor has released WP Job Portal version 2.4.5, which patches this vulnerability. Site administrators should update the plugin to version 2.4.5 or later immediately. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated, and auto-update for vulnerable plugins can be enabled via the Patchstack dashboard (Patchstack).

Community reactions

Patchstack, which coordinated the disclosure after researcher benzdeus reported the vulnerability on October 29, 2025, classified it as high priority and noted its potential for mass exploitation campaigns. The vulnerability was also noted on Bluesky by The Hacker Wire and aggregated by several CVE tracking services shortly after publication (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93031HIGH8.8
  • use-your-drive
NoYesSep 18, 2026
CVE-2026-87915HIGH7.2
  • popup-maker
NoYesSep 18, 2026
CVE-2026-18405HIGH7.2
  • jeg-elementor-kit
NoYesSep 18, 2026
CVE-2026-15797MEDIUM6.4
  • popup-maker
NoYesSep 18, 2026
CVE-2026-90884MEDIUM5.4
  • wp-recipe-maker
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management