CVE-2025-14467

Publication date

2025-12-12 03:20:39

Family

Wordfence

State

PUBLISHED

Description

The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.3.9. This is due to the plugin explicitly whitelisting the `