plugin

Jobcareer Vulnerabilities

6 known security issues reported for the Jobcareer WordPress plugin. Most recent disclosed Mar 13, 2025.

2 high 4 medium

Running Jobcareer on your site? Check whether your installed version is affected.

Scan your site free

JobCareer | Job Board Responsive WordPress Theme <= 7.1 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrative Actions

high

The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 7.1. This makes it possible for authenticated attackers, with Subscriber-level acce...

CVSS:
8.8
Affected:
up to 7.1
Fix:
No patched version reported
Disclosed:
Mar 13, 2025

CVE-2024-12810 on NVD →

JobCareer <= 3.4 - Multiple Cross-Site Scripting

medium

The JobCareer | Job Board Responsive plugin for WordPress is vulnerable to both authenticated Stored and unauthenticated Reflected Cross-Site Scripting in versions up to, and including, 3.4 due to insufficient input sanitization and output escaping. The Reflected XSS is vulnerable to the following parameters: 'job_titl...

CVSS:
6.4
Affected:
up to 3.4
Fixed in:
3.5
Disclosed:
Jul 24, 2020

JobCareer <= 3.4 - Cross-Site Scripting

medium

The JobCareer plugin for WordPress is vulnerable to Cross-Site Scripting via the 'job_title', 'specialisms', and 'location' parameters and address textfield in versions up to, and including, 3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...

CVSS:
6.1
Affected:
up to 3.4
Fixed in:
3.5
Disclosed:
Jul 24, 2020

JobCareer | Job Board Responsive WordPress Theme <= 2.5.1 - Stored Cross-Site Scripting

medium

The JobCareer theme before 2.5.1 for WordPress has stored XSS.

CVSS:
6.4
Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Apr 24, 2019

CVE-2019-15869 on NVD →

JobCareer | Job Board Responsive WordPress Theme < 2.4 - Unauthenticated Arbitrary Password Reset

high

The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's account.

CVSS:
8.8
Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Dec 4, 2018

CVE-2018-19488 on NVD →

JobCareer | Job Board Responsive WordPress Theme < 2.4 - User Enumeration

medium

The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.

CVSS:
5.3
Affected:
up to 2.4
Fixed in:
2.4.1
Disclosed:
Dec 4, 2018

CVE-2018-19487 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database