Arbitrary File Deletion Vulnerability in WP Job Portal Plugin by WordPress
CVE-2026-4758
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 March 2026
What is CVE-2026-4758?
The WP Job Portal plugin for WordPress contains a vulnerability that allows authenticated users with Subscriber-level access or higher to delete arbitrary files from the server. This vulnerability stems from inadequate file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function. If exploited, attackers could potentially delete critical files, such as wp-config.php, increasing the risk of remote code execution and further compromise of the WordPress installation.
Affected Version(s)
WP Job Portal β AI-Powered Recruitment System for Company or Job Board website 0 <= 2.4.9