Boletines de Vulnerabilidades |
CVE-2026-12397 |
|
| Software afectado | WORDPRESS |
| The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account email addresses by enumerating job identifiers. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-12397 | |














