JS Job Manager <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The JS Job Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 6.4
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Sep 22, 2025
CVE-2025-58234 on NVD →
JS Job Manager [js-jobs] <= 2.0.2 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Job Manager allows SQL Injection. This issue affects JS Job Manager: from n/a through 2.0.2.
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2025-32626 on NVD →
JS Job Manager [js-jobs] <= 2.0.2 (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager allows Upload a Web Shell to a Web Server. This issue affects JS Job Manager: from n/a through 2.0.2.
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2025-32660 on NVD →
JS Job Manager <= 2.0.2 - Unauthenticated SQL Injection
high
The JS Job Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...
- CVSS:
- 7.5
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 15, 2025
CVE-2025-32626 on NVD →
JS Job Manager <= 2.0.2 - Unauthenticated Arbitrary File Upload
critical
The JS Job Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- CVSS:
- 9.8
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 14, 2025
CVE-2025-32660 on NVD →
JS Job Manager [js-jobs] <= 2.0.2 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Job Manager allows PHP Local File Inclusion. This issue affects JS Job Manager: from n/a through 2.0.2.
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 11, 2025
CVE-2025-32627 on NVD →
JS Job Manager <= 2.0.2 - Unauthenticated Local File Inclusion
critical
The JS Job Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contr...
- CVSS:
- 9.8
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2025
CVE-2025-32627 on NVD →
JS Job Manager <= 2.0.2 - Authenticated (Contributor+) Local File Inclusion
high
The JS Job Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files....
- CVSS:
- 8.8
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32146 on NVD →
JS Job Manager [js-jobs] <= 2.0.2 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Job Manager allows PHP Local File Inclusion. This issue affects JS Job Manager: from n/a through 2.0.2.
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32146 on NVD →
JS Job Manager <= 2.0.2 - Missing Authorization
medium
The JS Job Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31868 on NVD →
JS Job Manager <= 2.0.2 - Authenticated Insecure Direct Object Reference
medium
The JS Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.2 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Custom-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31867 on NVD →
JS Job Manager [js-jobs] <= 2.0.2 (unfixed)
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Job Manager: from n/a through 2.0.2.
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31867 on NVD →
JS Job Manager [js-jobs] <= 2.0.2 (unfixed)
unknown
[en] Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Job Manager: from n/a through 2.0.2.
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31868 on NVD →
JS Job Manager [js-jobs] < 2.0.1
unknown
[en] Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through 2.0.0.
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- Dec 9, 2024
CVE-2023-28689 on NVD →
JS Job Manager [js-jobs] < 2.0.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions.
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- Nov 9, 2023
CVE-2023-31087 on NVD →
JS Job Manager [js-jobs] < 2.0.1
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions.
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- Jun 16, 2023
CVE-2023-25963 on NVD →
JS Job Manager <= 2.0.0 - Cross-Site Request Forgery via multiple functions
medium
The JS Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation on a large number of functions in the plugin. This makes it possible for unauthenticated attackers to make use of nearly all the administrativ...
- CVSS:
- 5.4
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.1
- Disclosed:
- Jun 2, 2023
CVE-2023-31087 on NVD →
JS Job Manager <= 2.0.0 - Missing Authorization
medium
The JS Job Manager plugin for WordPress is vulnerable to unauthorized access to plugin functionality due to missing capability checks on several functions called via AJAX actions in versions up to, and including, 2.0.0. This makes it possible for authenticated attackers with subscriber-level access, and above, to make...
- CVSS:
- 6.5
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.1
- Disclosed:
- Mar 21, 2023
CVE-2023-28689 on NVD →
JS Job Manager <= 2.0.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via title
medium
The JS Job Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title parameter in versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level access, and above, to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.1
- Disclosed:
- Feb 21, 2023
CVE-2023-25963 on NVD →
JS Job Manager < 1.1.9 - Arbitrary Plugin Installation/Activation
critical
The JS Job Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jsjobs_ajax function in versions before 1.1.9. This makes it possible for unauthenticated attackers to arbitrarily install and activate plugins.
- CVSS:
- 9.1
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9
- Disclosed:
- Sep 30, 2021
JS Job Manager [js-jobs] < 1.1.9
unknown
The JS Job Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jsjobs_ajax function in versions before 1.1.9. This makes it possible for unauthenticated attackers to arbitrarily install and activate plugins.
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9
- Disclosed:
- Sep 30, 2021
JS Job Manager [js-jobs] < 1.0.7
unknown
[en] The js-jobs plugin before 1.0.7 for WordPress has CSRF.
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
- Disclosed:
- Aug 16, 2019
CVE-2018-20974 on NVD →
JS Job Manager <= 1.0.6 - Cross-Site Request Forgery
high
The JS Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request grant...
- CVSS:
- 8.8
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.7
- Disclosed:
- May 28, 2018
CVE-2018-20974 on NVD →
JS Job Manager [js-jobs] < 1.1.9
unknown
The jsjobs_ajax AJAX action of the plugin available to both authenticated and unauthenticated users does not have proper authorisation and CSRF checks, in particular when using the installPluginFromAjax and activatePluginFromAjax, which could allow unauthenticated attackers to install arbitrary plugins from the WordPre...
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9
JS Job Manager [js-jobs] <= 2.0.2 (unfixed)
unknown
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
CVE-2025-58234 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database