CVE-2026-81299: WordPress WP Job Portal plugin <= 2.5.9 - Insecure Direct Object References (IDOR) vulnerability
Published Aug 28, 2026
·Updated
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
Affected Software
1 affected component
WP Job Portal<=2.5.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Job Portalto a version that resolves this vulnerability.Fixed in 2.6.0
Event History
Aug 28, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The vulnerability is associated with Subscriber-level access, so exploitation requires a low-privileged authenticated account. It can be exploited over the network and does not require user interaction.
2
What is the expected security impact?
The assigned vector indicates a low integrity impact. No confidentiality or availability impact is indicated.