Ahmad WP Job Portal是Ahmad的职位门户插件。 Ahmad WP Job Portal 2.5.5之前版本存在授权问题漏洞,该漏洞源于未执行能力或所有权检查,可能导致已验证用户(订阅者级别账户)批准、推荐或拒绝任意工作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Job Portal | < 2.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Job Portal | 0 ~ 2.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12275 | Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content | |
| CVE-2026-12397 | WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR | |
| CVE-2026-12582 | Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id | |
| CVE-2026-11964 | User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verifica | |
| CVE-2026-12081 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object | |
| CVE-2026-12273 | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation | |
| CVE-2026-12271 | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR | |
| CVE-2026-12274 | Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR | |
| CVE-2026-11963 | User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier M | |
| CVE-2026-10551 | Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library |
No comments yet