CVE-2024-11712: Wpjobportal Wp Job Portal
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to download other users resumes.
Affected products
- Wpjobportal Wp Job Portal: before 2.2.3 (fixed in 2.2.3)
Published 2024-12-14. Last modified 2026-06-17.