CVE-2026-12395: WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter
The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with a subscriber-level (self-registerable) account to perform SQL injection attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12395?
CVE-2026-12395 has a risk rating of 55, indicating a medium severity level.
How do I fix CVE-2026-12395?
To fix CVE-2026-12395, upgrade the WP Job Portal plugin to version 2.5.5 or later.
Who is affected by CVE-2026-12395?
CVE-2026-12395 affects WordPress WP Job Portal plugin versions prior to 2.5.5 and allows authenticated users with subscriber-level access to exploit it.
What type of attack is associated with CVE-2026-12395?
CVE-2026-12395 is associated with SQL Injection attacks via the 'ta' parameter in applied resumes.
What specific component is vulnerable in CVE-2026-12395?
CVE-2026-12395 is vulnerable due to improper sanitization and escaping of a parameter used in SQL queries.