Job Manager <= 0.7.25 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 0.7.25. T...
- CVSS:
- 5.5
- Affected:
- up to 0.7.25
- Fix:
- No patched version reported
- Disclosed:
- Oct 14, 2021
CVE-2021-39336 on NVD →
Job Manager <= 0.7.25 - Insecure Direct Object Reference
high
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.
- CVSS:
- 7.5
- Affected:
- up to 0.7.25
- Fix:
- No patched version reported
- Disclosed:
- Aug 28, 2015
CVE-2015-6668 on NVD →
Job Manager <= 0.7.24 - Reflected Cross-Site Scripting
high
The Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘jobman-rating’ parameter in versions up to, and including, 0.7.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...
- CVSS:
- 7.1
- Affected:
- up to 0.7.25
- Fixed in:
- 0.7.25
- Disclosed:
- Aug 25, 2015
Job Manager - < 0.7.23 - Stored Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the email field.
- CVSS:
- 6.1
- Affected:
- up to 0.7.23
- Fixed in:
- 0.7.23
- Disclosed:
- Aug 4, 2015
CVE-2015-2321 on NVD →
Job Manager <= 0.7.18 - Cross-Site Scripting
medium
The Job Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.7.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 0.7.18
- Fixed in:
- 0.7.19
- Disclosed:
- Jun 28, 2012
CVE-2012-6713 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database