JobCareer | Job Board Responsive WordPress Theme <= 7.1 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrative Actions
high
The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 7.1. This makes it possible for authenticated attackers, with Subscriber-level acce...
- CVSS:
- 8.8
- Affected:
- up to 7.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 13, 2025
CVE-2024-12810 on NVD →
JobCareer <= 3.4 - Multiple Cross-Site Scripting
medium
The JobCareer | Job Board Responsive plugin for WordPress is vulnerable to both authenticated Stored and unauthenticated Reflected Cross-Site Scripting in versions up to, and including, 3.4 due to insufficient input sanitization and output escaping. The Reflected XSS is vulnerable to the following parameters: 'job_titl...
- CVSS:
- 6.4
- Affected:
- up to 3.4
- Fixed in:
- 3.5
- Disclosed:
- Jul 24, 2020
JobCareer <= 3.4 - Cross-Site Scripting
medium
The JobCareer plugin for WordPress is vulnerable to Cross-Site Scripting via the 'job_title', 'specialisms', and 'location' parameters and address textfield in versions up to, and including, 3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- CVSS:
- 6.1
- Affected:
- up to 3.4
- Fixed in:
- 3.5
- Disclosed:
- Jul 24, 2020
JobCareer | Job Board Responsive WordPress Theme <= 2.5.1 - Stored Cross-Site Scripting
medium
The JobCareer theme before 2.5.1 for WordPress has stored XSS.
- CVSS:
- 6.4
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- Apr 24, 2019
CVE-2019-15869 on NVD →
JobCareer | Job Board Responsive WordPress Theme < 2.4 - Unauthenticated Arbitrary Password Reset
high
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's account.
- CVSS:
- 8.8
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Dec 4, 2018
CVE-2018-19488 on NVD →
JobCareer | Job Board Responsive WordPress Theme < 2.4 - User Enumeration
medium
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.
- CVSS:
- 5.3
- Affected:
- up to 2.4
- Fixed in:
- 2.4.1
- Disclosed:
- Dec 4, 2018
CVE-2018-19487 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database