CVE-2025-48273: WordPress WP Job Portal plugin <= 2.3.2 - Arbitrary File Download Vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Path Traversal.This issue affects WP Job Portal: from n/a through <= 2.3.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48273?
CVE-2025-48273 has a medium severity rating due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2025-48273?
To fix CVE-2025-48273, upgrade the WP Job Portal to version 2.3.3 or later, which contains the necessary security patches.
What types of systems are affected by CVE-2025-48273?
CVE-2025-48273 affects all versions of WP Job Portal from n/a through 2.3.2 when installed on WordPress.
What kind of attack can be executed using CVE-2025-48273?
Exploitation of CVE-2025-48273 can allow attackers to conduct path traversal attacks, potentially accessing files outside the intended directory.
Is there a workaround for CVE-2025-48273 if I cannot update immediately?
A temporary workaround for CVE-2025-48273 is to disable the WP Job Portal plugin until an update can be applied.