
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website Security & Risk Analysis
wordpress.org/plugins/wp-job-portalA smart, AI-powered job board plugin for WordPress. Build modern recruitment platforms with job listings, resume search, and intelligent matching.
Is WP Job Portal – AI-Powered Recruitment System for Company or Job Board website Safe to Use in 2026?
High Risk
Score 40/100WP Job Portal – AI-Powered Recruitment System for Company or Job Board website carries significant security risk with 34 known CVEs, 1 still unpatched. Consider switching to a maintained alternative.
The "wp-job-portal" plugin version 2.4.8 presents a significant security risk. While the code exhibits some good practices, such as a high percentage of prepared SQL statements and properly escaped output, these are overshadowed by critical vulnerabilities in its attack surface and a concerning history of security issues. The presence of 8 unprotected AJAX handlers provides a wide entry point for unauthenticated attacks. Furthermore, the taint analysis revealed 11 high-severity flows with unsanitized paths, indicating a strong potential for serious vulnerabilities like path traversal or remote file inclusion if these flows are exposed to user input. The plugin's history of 32 known CVEs, including 3 critical and 4 high-severity ones, with one currently unpatched, is particularly alarming. This pattern suggests a recurring tendency to introduce or fail to fix significant security flaws, with common vulnerability types including XSS, path traversal, authorization bypass, and RFI. The last reported vulnerability date of 2026-02-03 is also concerningly recent and implies ongoing or new issues not yet addressed in this version.
Key Concerns
- Unprotected AJAX handlers
- High-severity taint flows
- Unpatched CVEs
- Multiple critical CVEs
- Multiple high CVEs
- Commonly exploited vulnerability types (XSS, Path Traversal, RFI)
- Dangerous function: unserialize
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website Security Vulnerabilities
CVEs by Year
Severity Breakdown
34 total CVEs
WP Job Portal <= 2.4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field
WP Job Portal <= 2.4.8 - Unauthenticated SQL Injection via 'radius' Parameter
WP Job Portal <= 2.4.4 - Missing Authorization
Job Portal <= 2.4.3 - Authenticated (Subscriber+) Insecure Direct Object Reference
WP Job Portal <= 2.4.4 - Authenticated (Editor+) Stored Cross-Site Scripting via Job Description Field
WP Job Portal <= 2.4.0 - Authenticated (Subscriber+) Arbitrary File Read
WP Job Portal <= 2.3.2 - Unauthenticated SQL Injection
WP Job Portal <= 2.3.2 - Unauthenticated Arbitrary File Download
WP Job Portal <= 2.3.2 - Unauthenticated Insecure Direct Object Reference
WP Job Portal <= 2.3.1 - Unauthenticated Local File Inclusion
WP Job Portal <= 2.2.8 - Authenticated (Contributor+) Local File Inclusion
WP Job Portal <= 2.2.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Photo Disconnection
WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Job Deletion
WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Company Deletion
WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Company Logo Deletion
WP Job Portal <= 2.2.6 - Missing Authorization to Unauthenticated Arbitrary Email Sending
WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Arbitrary Resume Download
WP Job Portal – A Complete Recruitment System for Company or Job Board website <= 2.2.5- Authenticated (Subscriber+) Insecure Direct Object Reference
WP Job Portal – A Complete Recruitment System for Company or Job Board website <= 2.2.4 - Authenticated (Subscriber+) Insecure Direct Object Reference
WP Job Portal <= 2.2.2 - Missing Authorization to Limited Privilege Escalation
WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection via wpjobportal_deactivate()
WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection via getFieldsForVisibleCombobox()
WP Job Portal <= 2.2.1 - Unauthenticated SQL Injection
WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection
WP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume Download
WP Job Portal <= 2.2.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting
WP Job Portal <= 2.1.6 - Missing Authorization to Unauthenticated Local File Inclusion, Arbitrary Settings Update, and User Creation
WP Job Portal <= 2.1.8 - Authenticated (Subscriber+) Insecure Direct Object Reference
WP Job Portal <= 2.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Job Portal <= 2.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Job Portal <= 2.0.6 - Cross-Site Request Forgery
WP Job Portal <= 2.0.5 - Unauthenticated SQL Injection
WP Job Portal <= 2.0.1 - Cross-Site Request Forgery to Settings Modification
WP Job Portal <= 2.0.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website Release Timeline
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website Attack Surface
AJAX Handlers 8
Shortcodes 33
WordPress Hooks 121
Scheduled Events 1
Maintenance & Trust
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website Maintenance & Trust
Maintenance Signals
Community Trust
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website Alternatives
Simple Job Board
simple-job-board
job board plugin for job listings, managing applicants, applications, categories, job types, taxonomies, career page, job openings, and recruiters
WP Job Openings – Job Listing, Career Page and Recruitment Plugin
wp-job-openings
WP Job Openings plugin is the most simple yet powerful plugin for setting up a job listing page for your WordPress website.
Auto Delete Applications – Add-on for WP Job Openings
auto-delete-applications-add-on-for-wp-job-openings
This is an add-on for WP Job Openings Plugin, which will let you delete the received applications periodically. The plugin will let you specify a time …
JobPress – Your Company Job Board & Career Page
jobpress
JobPress is the ultimate WordPress job board plugin for a company.
Binary Job Listing – WordPress Clean and Modern Job Listing, Career Page
binary-job-listing
Binary Job Listing is the most powerful and incredibly feature-packed, advanced recruitment plugin that comes with gorgeous designs and has everything …
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website Developer Profile
1 plugin · 8K total installs
How We Detect WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-job-portal/css/bootstrap.min.css/wp-content/plugins/wp-job-portal/css/jobportal.css/wp-content/plugins/wp-job-portal/css/jquery.dataTables.min.css/wp-content/plugins/wp-job-portal/css/jquery-ui.css/wp-content/plugins/wp-job-portal/css/datepicker.css/wp-content/plugins/wp-job-portal/css/colorpicker.css/wp-content/plugins/wp-job-portal/css/custom_color.css/wp-content/plugins/wp-job-portal/css/wpjpcustomfields.css+12 more/wp-content/plugins/wp-job-portal/js/jobportal.js/wp-content/plugins/wp-job-portal/js/jquery.validate.min.js/wp-content/plugins/wp-job-portal/js/jquery.dataTables.min.js/wp-content/plugins/wp-job-portal/js/datepicker.js/wp-content/plugins/wp-job-portal/js/bootstrap-select.js/wp-content/plugins/wp-job-portal/js/jquery.colorpicker.js+4 morewp-job-portal/style.css?ver=wp-job-portal/js/jobportal.js?ver=wp-job-portal/js/jquery.validate.min.js?ver=wp-job-portal/js/jquery.dataTables.min.js?ver=wp-job-portal/js/datepicker.js?ver=wp-job-portal/js/bootstrap-select.js?ver=wp-job-portal/js/jquery.colorpicker.js?ver=wp-job-portal/js/custom_color.js?ver=wp-job-portal/js/wpjpcustomfields.js?ver=wp-job-portal/js/bootstrap.min.js?ver=wp-job-portal/js/bootstrap-datepicker.js?ver=HTML / DOM Fingerprints
wpjobportal<!-- Restricted Access --><!-- PDF Change --><!-- Only for the pdf in wordpress --><!-- for post installation screens -->+5 moredata-targetdata-toggleWPJOBPORTAL