Access Control Weakness in WP Job Portal by WordPress
CVE-2026-24941
7.5HIGH
What is CVE-2026-24941?
A Missing Authorization vulnerability has been identified in the WP Job Portal plugin for WordPress, which allows for the exploitation of incorrectly configured access control security levels. This weakness can permit unauthorized users to gain access to restricted functionalities within the plugin, potentially leading to unauthorized actions and data exposure. The issue affects versions of the WP Job Portal plugin from release n/a up to and including version 2.4.4. It is essential for users to review their access control settings and update to a secure version to mitigate risks.
Affected Version(s)
WP Job Portal 0 <= 2.4.4