CVE-2026-42684: WordPress WP Job Portal plugin <= 2.5.1 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection.
This issue affects WP Job Portal: from n/a through 2.5.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Job Portal pluginto a version that resolves this vulnerability.Fixed in 2.5.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42684?
CVE-2026-42684 has a critical severity rating of 9.3.
How do I fix CVE-2026-42684?
To fix CVE-2026-42684, update the WordPress WP Job Portal plugin to version 2.5.2 or later.
What type of vulnerability is CVE-2026-42684?
CVE-2026-42684 is an SQL Injection vulnerability that allows for Blind SQL Injection.
Which versions of the WP Job Portal plugin are affected by CVE-2026-42684?
CVE-2026-42684 affects all versions of the WP Job Portal plugin up to and including 2.5.1.
Who is affected by CVE-2026-42684?
Users of the Ahmad WP Job Portal plugin version 2.5.1 and earlier are affected by CVE-2026-42684.