---
id: CVE-2025-14293
title: >-
  The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in
  all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile'
  function
summary: >-
  The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in
  all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile'
  function. This makes it possible for authenticated attackers, with
  Subscriber-le…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14293'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-job-portal/tags/2.3.9/modules/customfield/model.php#L908
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-job-portal/tags/2.4.1/modules/customfield/model.php#L908
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/6dfcd264-39e3-44af-8e0e-5c35734524d0?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00365
epssPercentile: 0.28173
ingestedAt: '2026-10-07T20:46:46.864Z'
---

## Overview

The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
