CVE-2026-25404

WordPress WP Job Manager plugin <= 2.4.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Automattic WP Job Manager wp-job-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Manager: from n/a through <= 2.4.0.


We have discovered 2,003 live websites that are affected by CVE-2026-25404.

Run a Free Instant Scan




Affected Software

Product  WP Job Manager
Category Wordpress Plugins
Vulnerable Domains2,003 live websites (53% of WP Job Manager install base)
Vulnerable Versions
  • from 0 through 2.4
Vulnerable Versions Count53 versions ( 87% of all versions)



Details

  • Published - Feb 19, 2026
  • Updated - Apr 1, 2026

Credits

  • Tristan Jay Neale | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-25404
United States645 websites



Germany199 websites
France157 websites
GB115 websites
Italy86 websites
Spain62 websites
Netherlands57 websites
Canada57 websites
Russia40 websites
India40 websites

Website Distribution by TLD

Number of websites using CVE-2026-25404
.com886 websites
.de114 websites
.org84 websites
.co.uk66 websites
.it63 websites
.fr59 websites
.nl45 websites
.net44 websites
.com.au37 websites
.ru34 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-25404

Top websites that are affected by CVE-2026-25404. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com United States**,***
*********.com United States**,***
*******.com GB***,***
****************.se Sweden***,***
******.com United States***,***
*******.org United States***,***
****.com United States***,***
****.org GB***,***
***********.com United States***,***
*********.************.com United States***,***
See full domain list

FAQ

A total of 2,003 websites have been identified as vulnerable to CVE-2026-25404, based on global website indexing conducted by WebTechSurvey.
The WP Job Manager is affected by the CVE-2026-25404 vulnerability.
WP Job Manager versions up to and including 2.4 are vulnerable to CVE-2026-25404.