CVE-2026-4758: WP Job Portal <= 2.4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field
The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4758?
CVE-2026-4758 is considered a high severity vulnerability due to the potential for arbitrary file deletion.
How do I fix CVE-2026-4758?
To fix CVE-2026-4758, update the WP Job Portal plugin to version 2.5.0 or later.
What software is affected by CVE-2026-4758?
CVE-2026-4758 affects the WP Job Portal plugin versions up to and including 2.4.9.
What type of vulnerability is CVE-2026-4758?
CVE-2026-4758 is an arbitrary file deletion vulnerability due to insufficient file path validation.
Who can exploit CVE-2026-4758?
CVE-2026-4758 can be exploited by authenticated users with Subscriber or higher roles.