Jobs for WordPress Plugin Vulnerability (CVE-2026-39752)

On this page

Security Alert Summary

The Jobs for WordPress plugin (versions up to and including 2.8.2) contains a vulnerability that allows users with the Contributor role to perform arbitrary file deletion. The issue can result in loss of files or site disruption (availability impact) without requiring user interaction.


CVE Details

  • CVE ID: CVE-2026-39752
  • Affected product: Jobs for WordPress (plugin package name: job-postings) by BlueGlass Interactive AG
  • Affected versions: Versions <= 2.8.2
  • Published: October 6, 2026 at 9:17:46 AM
  • Last modified: October 6, 2026 at 3:04:25 PM
  • Vulnerability status: Deferred
  • CVSS v3.1 base score: 7.7 (HIGH)
  • Vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
  • Authentication / privileges / user interaction:
    • Privileges required: Low (an authenticated user with Contributor privileges)
    • User interaction: None
    • Attack vector: Network
  • Primary impact: Confidentiality: None; Integrity: None; Availability: High
  • CWE / weakness ID: CWE-22 (Path Traversal)

Technical Details

The reported issue is an arbitrary file deletion vulnerability exploitable by accounts with the Contributor role. The presence of CWE-22 indicates a path traversal or insufficient pathname restriction that allows deletion of files outside the intended directory. Because the vulnerability requires only low privileges and no user interaction, a contributor may trigger deletions that affect site files or content.

No specific functions or REST API endpoints are named in the available data. The technical root cause, as indicated by the weakness classification, is inadequate validation or restriction of file paths when performing deletion operations.

Impact is primarily on availability: deleted files could include job listings, uploaded assets, or plugin files, causing content loss, rendering errors, or partial site downtime. There is no CVSS-indicated impact to confidentiality or integrity in the provided data.


How This Could Impact Your Website

Imagine a typical small business WordPress site with the site owner, an internal content editor, and an external contractor granted Contributor access to submit job listings. If the contractor account is able to delete files beyond their intended scope, the site owner could see job listings, media files, or plugin assets removed unexpectedly. That deletion can disrupt recruitment workflows, remove public-facing content, and cause service interruptions while files are restored from backups.

Per the CVSS data, this issue does not directly expose internal user emails or other confidential data (Confidentiality: None). However, disruption to normal communications or publishing workflows could indirectly increase the risk of social engineering or targeted phishing if attackers try to exploit the interruption. If you\’re unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review of your setup.


Recommended Actions

  • Update the affected plugin as soon as a patched version is available.
  • Review and reduce unnecessary user roles, especially Contributor accounts that do not need file-related capabilities.
  • Enforce strong passwords and enable two-factor authentication for editors and administrators.
  • Remove unused or unmaintained plugins to reduce the attack surface.
  • Monitor site activity and logs for unusual deletion events or file changes, and ensure reliable backups are in place and tested.

If you\’d like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.


References