plugin

Js Jobs Vulnerabilities

25 known security issues reported for the Js Jobs WordPress plugin. Most recent disclosed Sep 22, 2025.

3 critical 3 high 6 medium

Running Js Jobs on your site? Check whether your installed version is affected.

Scan your site free

JS Job Manager <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The JS Job Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Sep 22, 2025

CVE-2025-58234 on NVD →

JS Job Manager [js-jobs] <= 2.0.2 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Job Manager allows SQL Injection. This issue affects JS Job Manager: from n/a through 2.0.2.

Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-32626 on NVD →

JS Job Manager [js-jobs] <= 2.0.2 (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager allows Upload a Web Shell to a Web Server. This issue affects JS Job Manager: from n/a through 2.0.2.

Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-32660 on NVD →

JS Job Manager <= 2.0.2 - Unauthenticated SQL Injection

high

The JS Job Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...

CVSS:
7.5
Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 15, 2025

CVE-2025-32626 on NVD →

JS Job Manager <= 2.0.2 - Unauthenticated Arbitrary File Upload

critical

The JS Job Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS:
9.8
Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 14, 2025

CVE-2025-32660 on NVD →

JS Job Manager [js-jobs] <= 2.0.2 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Job Manager allows PHP Local File Inclusion. This issue affects JS Job Manager: from n/a through 2.0.2.

Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 11, 2025

CVE-2025-32627 on NVD →

JS Job Manager <= 2.0.2 - Unauthenticated Local File Inclusion

critical

The JS Job Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contr...

CVSS:
9.8
Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 9, 2025

CVE-2025-32627 on NVD →

JS Job Manager <= 2.0.2 - Authenticated (Contributor+) Local File Inclusion

high

The JS Job Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files....

CVSS:
8.8
Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32146 on NVD →

JS Job Manager [js-jobs] <= 2.0.2 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Job Manager allows PHP Local File Inclusion. This issue affects JS Job Manager: from n/a through 2.0.2.

Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32146 on NVD →

JS Job Manager <= 2.0.2 - Missing Authorization

medium

The JS Job Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31868 on NVD →

JS Job Manager <= 2.0.2 - Authenticated Insecure Direct Object Reference

medium

The JS Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.2 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Custom-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31867 on NVD →

JS Job Manager [js-jobs] <= 2.0.2 (unfixed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Job Manager: from n/a through 2.0.2.

Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31867 on NVD →

JS Job Manager [js-jobs] <= 2.0.2 (unfixed)

unknown

[en] Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Job Manager: from n/a through 2.0.2.

Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31868 on NVD →

JS Job Manager [js-jobs] < 2.0.1

unknown

[en] Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through 2.0.0.

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Dec 9, 2024

CVE-2023-28689 on NVD →

JS Job Manager [js-jobs] < 2.0.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions.

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Nov 9, 2023

CVE-2023-31087 on NVD →

JS Job Manager [js-jobs] < 2.0.1

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions.

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Jun 16, 2023

CVE-2023-25963 on NVD →

JS Job Manager <= 2.0.0 - Cross-Site Request Forgery via multiple functions

medium

The JS Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation on a large number of functions in the plugin. This makes it possible for unauthenticated attackers to make use of nearly all the administrativ...

CVSS:
5.4
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Jun 2, 2023

CVE-2023-31087 on NVD →

JS Job Manager <= 2.0.0 - Missing Authorization

medium

The JS Job Manager plugin for WordPress is vulnerable to unauthorized access to plugin functionality due to missing capability checks on several functions called via AJAX actions in versions up to, and including, 2.0.0. This makes it possible for authenticated attackers with subscriber-level access, and above, to make...

CVSS:
6.5
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Mar 21, 2023

CVE-2023-28689 on NVD →

JS Job Manager <= 2.0.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via title

medium

The JS Job Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title parameter in versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level access, and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Feb 21, 2023

CVE-2023-25963 on NVD →

JS Job Manager < 1.1.9 - Arbitrary Plugin Installation/Activation

critical

The JS Job Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jsjobs_ajax function in versions before 1.1.9. This makes it possible for unauthenticated attackers to arbitrarily install and activate plugins.

CVSS:
9.1
Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Sep 30, 2021

JS Job Manager [js-jobs] < 1.1.9

unknown

The JS Job Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jsjobs_ajax function in versions before 1.1.9. This makes it possible for unauthenticated attackers to arbitrarily install and activate plugins.

Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Sep 30, 2021

JS Job Manager [js-jobs] < 1.0.7

unknown

[en] The js-jobs plugin before 1.0.7 for WordPress has CSRF.

Affected:
up to 1.0.7
Fixed in:
1.0.7
Disclosed:
Aug 16, 2019

CVE-2018-20974 on NVD →

JS Job Manager <= 1.0.6 - Cross-Site Request Forgery

high

The JS Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request grant...

CVSS:
8.8
Affected:
up to 1.0.6
Fixed in:
1.0.7
Disclosed:
May 28, 2018

CVE-2018-20974 on NVD →

JS Job Manager [js-jobs] < 1.1.9

unknown

The jsjobs_ajax AJAX action of the plugin available to both authenticated and unauthenticated users does not have proper authorisation and CSRF checks, in particular when using the installPluginFromAjax and activatePluginFromAjax, which could allow unauthenticated attackers to install arbitrary plugins from the WordPre...

Affected:
up to 1.1.9
Fixed in:
1.1.9

JS Job Manager [js-jobs] <= 2.0.2 (unfixed)

unknown
Affected:
up to 2.0.2
Fix:
No patched version reported

CVE-2025-58234 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database