CVE-2025-48272: WordPress WP Job Portal plugin <= 2.3.2 - Insecure Direct Object References (IDOR) Vulnerability
Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.3.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48272?
CVE-2025-48272 is categorized as a Missing Authorization vulnerability, potentially allowing unauthorized access to sensitive data.
How do I fix CVE-2025-48272?
To fix CVE-2025-48272, update WP Job Portal to version 2.3.3 or later to address the incorrect access control configuration.
What versions of WP Job Portal are affected by CVE-2025-48272?
CVE-2025-48272 affects all versions of WP Job Portal from n/a through 2.3.2.
What are the potential impacts of CVE-2025-48272?
The potential impacts of CVE-2025-48272 include unauthorized access to job postings and user data, which can lead to data leakage.
How can I check if my site is vulnerable to CVE-2025-48272?
You can check if your site is vulnerable to CVE-2025-48272 by verifying if you are running WP Job Portal version 2.3.2 or earlier.