
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4758 is an arbitrary file deletion vulnerability in the WP Job Portal plugin for WordPress, affecting all versions up to and including 2.4.9. The flaw resides in the WPJOBPORTALcustomfields::removeFileCustom function, which fails to properly validate file paths before deletion. It was published on March 26, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, Red Hat CVE).
The root cause is improper limitation of a pathname to a restricted directory (CWE-22 / Path Traversal). The vulnerable function WPJOBPORTALcustomfields::removeFileCustom in includes/classes/customfields.php (line 1558) accepts user-supplied file path input without sufficient sanitization or boundary enforcement, allowing an attacker to traverse outside the intended directory and delete arbitrary files on the server. Exploitation requires only Subscriber-level authentication (a low-privilege WordPress account), and no user interaction is needed. Deleting critical files such as wp-config.php can trigger WordPress's setup mode, enabling an attacker to reconfigure the database connection and achieve remote code execution (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker with minimal privileges to delete any file accessible to the web server process, including sensitive configuration files like wp-config.php. Deletion of wp-config.php can force WordPress into installation mode, enabling the attacker to redirect the database to an attacker-controlled server and achieve full remote code execution. This results in high confidentiality, integrity, and availability impact — potentially leading to complete site takeover, data exfiltration, and persistent backdoor installation (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been confirmed as of the time of reporting. The EPSS score is approximately 0.278%, indicating a relatively low (but non-negligible) probability of exploitation in the near term. The vulnerability is detectable by Qualys (detection ID 531123) and has been indexed by multiple threat intelligence platforms. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, Qualys).
/wp-content/plugins/wp-job-portal/readme.txt.WPJOBPORTALcustomfields::removeFileCustom, supplying a path-traversal payload (e.g., ../../wp-config.php) as the file parameter to target critical server files.wp-config.php).wp-config.php deleted, WordPress enters setup/installation mode. The attacker navigates to the WordPress setup page and reconfigures the database connection to an attacker-controlled MySQL server, then completes installation to gain administrative access and execute arbitrary PHP code (Wordfence, WordPress Trac).../, %2e%2e%2f) in file-related parameters; repeated 200 responses to file removal actions from low-privilege accounts.wp-config.php in the WordPress root directory; unexpected deletion of other core WordPress files or plugin files; new or modified PHP files in the WordPress installation directory following the incident.wp-config.php or other critical files; WordPress setup/installation page (/wp-admin/setup-config.php) being accessed after initial site configuration.Users should update the WP Job Portal plugin to version 2.5.0 or later, which contains the fix for insufficient file path validation in the removeFileCustom function (WordPress Trac). As an interim workaround, site administrators should restrict new user registrations if not required, and limit Subscriber-level access to trusted users only. Additionally, implementing a Web Application Firewall (WAF) rule to block path-traversal patterns in file-related parameters can reduce exposure until patching is complete (Wordfence).
Wordfence published the vulnerability in their weekly WordPress vulnerability report for the week of March 23–29, 2026, highlighting it as a notable risk due to the low privilege requirement and potential for remote code execution via file deletion (Wordfence Blog). Red Packet Security and several CVE aggregator platforms (CVEFeed, VulDB, Infinitsec) also covered the disclosure shortly after publication. Social media activity was observed on Mastodon and Bluesky, primarily from automated CVE notification accounts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."