CVE-2026-12396
The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, all
CVSS
5.4
Medium
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Jul 13, 2026 · Last modified: Jul 13, 2026
0.2%EPSS · 30 days0.3%
2026-08-092026-09-06
The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary jobs, including those owned by other users.
No related CVEs by CWE or product.