CVE-2026-12397: WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR
The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account email addresses by enumerating job identifiers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12397?
The severity of CVE-2026-12397 is rated as medium with a CVSS score of 4.3.
How do I fix CVE-2026-12397?
To fix CVE-2026-12397, you should upgrade the WP Job Portal plugin to version 2.5.5 or above.
What does CVE-2026-12397 affect?
CVE-2026-12397 affects versions of the WP Job Portal WordPress plugin prior to 2.5.5.
Who is impacted by CVE-2026-12397?
Authenticated users with a subscriber-level account are impacted by CVE-2026-12397 as they can access other employers' private email addresses.
What type of vulnerability is CVE-2026-12397?
CVE-2026-12397 is an Insecure Direct Object Reference (IDOR) vulnerability that allows unauthorized access to email addresses.