Job Manager & Career – Manage job board listings, and recruitments <= 1.4.4 - Cross-Site Request Forgery to PHP Object Injection
high
The Job Manager & Career – Manage job board listings, and recruitments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on the save_plugin_settings() function. This makes it possible for unauthenticated att...
- CVSS:
- 8.8
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.5
- Disclosed:
- Dec 27, 2023
CVE-2023-51545 on NVD →
Job Manager & Career <= 1.4.3 - Sensitive Information Exposure
low
The Job Manager & Career – Manage job board listings, and recruitments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.3 in cases where directory listing is enabled. This makes it possible for unauthenticated attackers to extract sensitive data including up...
- CVSS:
- 3.7
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Nov 6, 2023
CVE-2023-5906 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database