SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-12397

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The WP Job Portal plugin for WordPress versions prior to 2.5.5 is vulnerable due to inadequate verification of ownership, enabling authenticated users with subscriber-level accounts to access private email addresses of other employers by enumerating job identifiers. This could lead to unauthorized disclosure of sensitive information, impacting user privacy. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-12397
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%
WordPress

Original NVD Description

The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account email addresses by enumerating job identifiers.