plugin

Job Board Vulnerabilities

8 known security issues reported for the Job Board WordPress plugin. Most recent disclosed Nov 25, 2025.

3 medium

Running Job Board on your site? Check whether your installed version is affected.

Scan your site free

Job Board by BestWebSoft [job-board] <= 1.2.1 (unfixed)

unknown

[en] The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.1. This is due to the plugin storing the entire unsanitized `$_GET` superglobal array directly into the database via `update_user_meta()` when users save search results, and late...

Affected:
up to 1.2.1
Fix:
No patched version reported
Disclosed:
Nov 25, 2025

CVE-2025-13383 on NVD →

Job Board by BestWebSoft <= 1.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via $_GET Array Storage

medium

The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.1. This is due to the plugin storing the entire unsanitized `$_GET` superglobal array directly into the database via `update_user_meta()` when users save search results, and later out...

CVSS:
6.1
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Nov 24, 2025

CVE-2025-13383 on NVD →

Job Board by BestWebSoft [job-board] < 1.0.1 (closed)

unknown

[en] A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is d...

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
May 2, 2023

CVE-2014-125100 on NVD →

Job Board by BestWebSoft [job-board] < 1.1.3 (closed)

unknown

[en] Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,...

Affected:
up to 1.1.3
Fixed in:
1.1.3
Disclosed:
May 22, 2017

CVE-2017-2171 on NVD →

Job Board by BestWebSoft < 1.1.4 - Reflected Cross-Site Scripting

medium

The Job Board by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

CVSS:
6.1
Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Apr 12, 2017

Job Board by BestWebSoft [job-board] < 1.1.4 (closed)

unknown

The Job Board by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Apr 12, 2017

Job Board by BestWebSoft <= 1.0.0 - Unauthenticated Stored Cross-Site Scripting

medium

The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bwsmn_form_email' parameter in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.5
Affected:
up to 1.0.0
Fixed in:
1.0.1
Disclosed:
Aug 8, 2014

CVE-2014-125100 on NVD →

Job Board by BestWebSoft [job-board] < 1.1.4 (closed)

unknown
Affected:
up to 1.1.4
Fixed in:
1.1.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database