CVE-2026-4758: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-4758 is an arbitrary file deletion vulnerability in the WP Job Portal plugin for WordPress, affecting all versions up to and including 2.4.9. The flaw resides in the WPJOBPORTALcustomfields::removeFileCustom function, which fails to properly validate file paths before deletion. It was published on March 26, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is improper limitation of a pathname to a restricted directory (CWE-22 / Path Traversal). The vulnerable function WPJOBPORTALcustomfields::removeFileCustom in includes/classes/customfields.php (line 1558) accepts user-supplied file path input without sufficient sanitization or boundary enforcement, allowing an attacker to traverse outside the intended directory and delete arbitrary files on the server. Exploitation requires only Subscriber-level authentication (a low-privilege WordPress account), and no user interaction is needed. Deleting critical files such as wp-config.php can trigger WordPress's setup mode, enabling an attacker to reconfigure the database connection and achieve remote code execution (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an authenticated attacker with minimal privileges to delete any file accessible to the web server process, including sensitive configuration files like wp-config.php. Deletion of wp-config.php can force WordPress into installation mode, enabling the attacker to redirect the database to an attacker-controlled server and achieve full remote code execution. This results in high confidentiality, integrity, and availability impact — potentially leading to complete site takeover, data exfiltration, and persistent backdoor installation (Wordfence, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been confirmed as of the time of reporting. The EPSS score is approximately 0.278%, indicating a relatively low (but non-negligible) probability of exploitation in the near term. The vulnerability is detectable by Qualys (detection ID 531123) and has been indexed by multiple threat intelligence platforms. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, Qualys).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running WP Job Portal plugin version ≤ 2.4.9 using tools like WPScan, Shodan, or by inspecting plugin metadata at /wp-content/plugins/wp-job-portal/readme.txt.
  2. Obtain low-privilege access: Register or obtain a Subscriber-level (or higher) WordPress account on the target site — many WordPress sites allow open registration.
  3. Authenticate: Log in to the WordPress site and obtain a valid authentication nonce or session cookie.
  4. Craft malicious request: Send an authenticated HTTP POST request to the endpoint invoking WPJOBPORTALcustomfields::removeFileCustom, supplying a path-traversal payload (e.g., ../../wp-config.php) as the file parameter to target critical server files.
  5. Trigger file deletion: The server processes the unsanitized path and deletes the specified file (e.g., wp-config.php).
  6. Achieve code execution: With wp-config.php deleted, WordPress enters setup/installation mode. The attacker navigates to the WordPress setup page and reconfigures the database connection to an attacker-controlled MySQL server, then completes installation to gain administrative access and execute arbitrary PHP code (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: Web server access logs showing authenticated POST requests to WP Job Portal endpoints with path-traversal sequences (e.g., ../, %2e%2e%2f) in file-related parameters; repeated 200 responses to file removal actions from low-privilege accounts.
  • File System: Absence of wp-config.php in the WordPress root directory; unexpected deletion of other core WordPress files or plugin files; new or modified PHP files in the WordPress installation directory following the incident.
  • Logs: WordPress debug logs or PHP error logs showing file-not-found errors for wp-config.php or other critical files; WordPress setup/installation page (/wp-admin/setup-config.php) being accessed after initial site configuration.
  • Network: Outbound connections from the web server to unknown external MySQL hosts (indicating database reconfiguration); unusual admin-level activity from previously low-privilege accounts.

Mitigation and workarounds

Users should update the WP Job Portal plugin to version 2.5.0 or later, which contains the fix for insufficient file path validation in the removeFileCustom function (WordPress Trac). As an interim workaround, site administrators should restrict new user registrations if not required, and limit Subscriber-level access to trusted users only. Additionally, implementing a Web Application Firewall (WAF) rule to block path-traversal patterns in file-related parameters can reduce exposure until patching is complete (Wordfence).

Community reactions

Wordfence published the vulnerability in their weekly WordPress vulnerability report for the week of March 23–29, 2026, highlighting it as a notable risk due to the low privilege requirement and potential for remote code execution via file deletion (Wordfence Blog). Red Packet Security and several CVE aggregator platforms (CVEFeed, VulDB, Infinitsec) also covered the disclosure shortly after publication. Social media activity was observed on Mastodon and Bluesky, primarily from automated CVE notification accounts.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management