The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpjobportal Wpjobportal wp Job Portal |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpjobportal Wpjobportal wp Job Portal |
Thu, 11 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. | |
| Title | WP Job Portal <= 2.4.0 - Authenticated (Subscriber+) Arbitrary File Read | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-12-11T20:22:09.209Z
Updated: 2025-12-11T21:18:15.841Z
Reserved: 2025-12-08T19:46:21.034Z
Link: CVE-2025-14293
Updated: 2025-12-11T21:16:51.635Z
Status : Awaiting Analysis
Published: 2025-12-11T21:15:46.730
Modified: 2025-12-12T15:17:31.973
Link: CVE-2025-14293
No data.