CVE-2025-26935: WordPress WP Job Portal plugin <= 2.2.8 - Local File Inclusion vulnerability
Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal: from n/a through <= 2.2.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26935?
CVE-2025-26935 is classified as a path traversal vulnerability that can lead to PHP Local File Inclusion, posing significant risk to affected systems.
How do I fix CVE-2025-26935?
To fix CVE-2025-26935, update the WP Job Portal plugin to version 2.2.9 or later to eliminate the vulnerability.
Which versions are affected by CVE-2025-26935?
CVE-2025-26935 affects WP Job Portal versions up to and including 2.2.8.
What impact can CVE-2025-26935 have on my website?
Exploitation of CVE-2025-26935 can allow an attacker to include local files, potentially leading to unauthorized access or code execution on your server.
Is CVE-2025-26935 remote or local?
CVE-2025-26935 is considered a remote vulnerability, as it can be exploited through malicious requests to the affected WP Job Portal plugin.