Job Board by BestWebSoft [job-board] <= 1.2.1 (unfixed)
unknown
[en] The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.1. This is due to the plugin storing the entire unsanitized `$_GET` superglobal array directly into the database via `update_user_meta()` when users save search results, and late...
- Affected:
- up to 1.2.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 25, 2025
CVE-2025-13383 on NVD →
Job Board by BestWebSoft <= 1.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via $_GET Array Storage
medium
The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.1. This is due to the plugin storing the entire unsanitized `$_GET` superglobal array directly into the database via `update_user_meta()` when users save search results, and later out...
- CVSS:
- 6.1
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Nov 24, 2025
CVE-2025-13383 on NVD →
Job Board by BestWebSoft [job-board] < 1.0.1 (closed)
unknown
[en] A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is d...
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- May 2, 2023
CVE-2014-125100 on NVD →
Job Board by BestWebSoft [job-board] < 1.1.3 (closed)
unknown
[en] Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,...
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.3
- Disclosed:
- May 22, 2017
CVE-2017-2171 on NVD →
Job Board by BestWebSoft < 1.1.4 - Reflected Cross-Site Scripting
medium
The Job Board by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- CVSS:
- 6.1
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Apr 12, 2017
Job Board by BestWebSoft [job-board] < 1.1.4 (closed)
unknown
The Job Board by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Apr 12, 2017
Job Board by BestWebSoft <= 1.0.0 - Unauthenticated Stored Cross-Site Scripting
medium
The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bwsmn_form_email' parameter in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.5
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.1
- Disclosed:
- Aug 8, 2014
CVE-2014-125100 on NVD →
Job Board by BestWebSoft [job-board] < 1.1.4 (closed)
unknown
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database