WP Job Portal <= 2.4.8 - Unauthenticated SQL Injection via 'radius' Parameter
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
Minimum safe version
2.5.0
Update to 2.5.0 or later to address 33 fixable vulnerabilities
WP Job Portal <= 2.4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field
CVE-2026-24941
Job Portal <= 2.4.3 - Authenticated (Subscriber+) Insecure Direct Object Reference
WP Job Portal <= 2.4.4 - Authenticated (Editor+) Stored Cross-Site Scripting via Job Description Field
CVE-2025-14293
CVE-2025-48274
WP Job Portal <= 2.3.2 - Unauthenticated Arbitrary File Download
CVE-2025-48272
CVE-2025-47438
CVE-2025-26935
CVE-2024-13873
CVE-2024-13428
CVE-2024-13372
CVE-2024-13371
CVE-2024-13425
CVE-2024-13429
CVE-2024-12131
CVE-2024-12132
CVE-2024-11711
CVE-2024-11715
CVE-2024-11713
CVE-2024-11712
CVE-2024-11710
CVE-2024-11714
CVE-2024-52389
CVE-2024-7950
CVE-2024-43266
CVE-2024-35760
CVE-2024-35759
WordPress WP Job Portal Plugin <= 2.0.6 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress WP Job Portal Plugin <= 2.0.5 is vulnerable to SQL Injection
CVE-2022-41786
CVE-2023-28534