CVE-2026-12396: Unknown Wp Job Portal

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary jobs, including those owned by other users.

Affected products

  • Unknown Wp Job Portal: before 2.5.5 (fixed in 2.5.5)

Published 2026-07-13. Last modified 2026-07-13.