plugin

Job Manager Vulnerabilities

5 known security issues reported for the Job Manager WordPress plugin. Most recent disclosed Oct 14, 2021.

2 high 3 medium

Running Job Manager on your site? Check whether your installed version is affected.

Scan your site free

Job Manager <= 0.7.25 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 0.7.25. T...

CVSS:
5.5
Affected:
up to 0.7.25
Fix:
No patched version reported
Disclosed:
Oct 14, 2021

CVE-2021-39336 on NVD →

Job Manager <= 0.7.25 - Insecure Direct Object Reference

high

The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.

CVSS:
7.5
Affected:
up to 0.7.25
Fix:
No patched version reported
Disclosed:
Aug 28, 2015

CVE-2015-6668 on NVD →

Job Manager <= 0.7.24 - Reflected Cross-Site Scripting

high

The Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘jobman-rating’ parameter in versions up to, and including, 0.7.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

CVSS:
7.1
Affected:
up to 0.7.25
Fixed in:
0.7.25
Disclosed:
Aug 25, 2015

Job Manager - < 0.7.23 - Stored Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the email field.

CVSS:
6.1
Affected:
up to 0.7.23
Fixed in:
0.7.23
Disclosed:
Aug 4, 2015

CVE-2015-2321 on NVD →

Job Manager <= 0.7.18 - Cross-Site Scripting

medium

The Job Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.7.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 0.7.18
Fixed in:
0.7.19
Disclosed:
Jun 28, 2012

CVE-2012-6713 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database