plugin

Simple Job Board Vulnerabilities

26 known security issues reported for the Simple Job Board WordPress plugin. Most recent disclosed Oct 22, 2025.

1 critical 3 high 9 medium

Running Simple Job Board on your site? Check whether your installed version is affected.

Scan your site free

Simple Job Board [simple-job-board] <= 2.13.7 (unfixed)

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows Retrieve Embedded Sensitive Data.This issue affects Simple Job Board: from n/a through <= 2.13.7.

Affected:
up to 2.13.7
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-59579 on NVD →

Simple Job Board <= 2.13.7 - Unauthenticated Sensitive Information Exposure

medium

The Simple Job Board plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.7. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.13.7
Fixed in:
2.13.8
Disclosed:
Oct 14, 2025

CVE-2025-59579 on NVD →

Simple Job Board [simple-job-board] < 2.10.6

unknown

[en] Missing Authorization vulnerability in PressTigers Simple Job Board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Job Board: from n/a through 2.10.5.

Affected:
up to 2.10.6
Fixed in:
2.10.6
Disclosed:
Jan 2, 2025

CVE-2023-47188 on NVD →

Simple Job Board <= 2.12.5 - Unauthenticated Resumes Download

medium

The Simple Job Board plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.12.5 due to insufficient access controls placed on the 'wp-content/uploads/jobpost/[YEAR]' directory. This makes it possible for unauthenticated attackers to download potentially sensitive resum...

CVSS:
5.3
Affected:
up to 2.12.5
Fixed in:
2.12.16
Disclosed:
Sep 13, 2024

CVE-2024-7762 on NVD →

Simple Job Board [simple-job-board] < 2.12.4

unknown

[en] The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known...

Affected:
up to 2.12.4
Fixed in:
2.12.4
Disclosed:
Aug 24, 2024

CVE-2024-7351 on NVD →

Simple Job Board <= 2.12.3 - Authenticated (Editor+) PHP Object Injection

high

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP...

CVSS:
7.2
Affected:
up to 2.12.3
Fixed in:
2.12.4
Disclosed:
Aug 23, 2024

CVE-2024-7351 on NVD →

Simple Job Board <= 2.12.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Simple Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 2.12.1
Fixed in:
2.12.2
Disclosed:
Jul 4, 2024

CVE-2024-7761 on NVD →

Simple Job Board [simple-job-board] < 2.11.1

unknown

[en] The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is...

Affected:
up to 2.11.1
Fixed in:
2.11.1
Disclosed:
Apr 9, 2024

CVE-2024-1813 on NVD →

Simple Job Board <= 2.11.0 - Unauthenticated PHP Object Injection via Job Application Fields

critical

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is prese...

CVSS:
9.8
Affected:
up to 2.11.0
Fixed in:
2.11.1
Disclosed:
Mar 15, 2024

CVE-2024-1813 on NVD →

Simple Job Board [simple-job-board] < 2.11.0

unknown

[en] The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password pro...

Affected:
up to 2.11.0
Fixed in:
2.11.0
Disclosed:
Feb 21, 2024

CVE-2024-0593 on NVD →

Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure

medium

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protecte...

CVSS:
5.3
Affected:
up to 2.10.8
Fixed in:
2.11.0
Disclosed:
Feb 20, 2024

CVE-2024-0593 on NVD →

Simple Job Board [simple-job-board] < 2.10.7

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board.This issue affects Simple Job Board: from n/a through 2.10.6.

Affected:
up to 2.10.7
Fixed in:
2.10.7
Disclosed:
Jan 5, 2024

CVE-2023-52122 on NVD →

Simple Job Board <= 2.10.6 - Cross-Site Request Forgery

medium

The Simple Job Board plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.6. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site...

CVSS:
4.3
Affected:
up to 2.10.6
Fixed in:
2.10.7
Disclosed:
Dec 28, 2023

CVE-2023-52122 on NVD →

Simple Job Board [simple-job-board] < 2.10.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board plugin <= 2.10.3 versions.

Affected:
up to 2.10.4
Fixed in:
2.10.4
Disclosed:
Nov 10, 2023

CVE-2023-29440 on NVD →

Simple Job Board <= 2.10.5 - Missing Authorization

medium

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.10.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.8
Affected:
up to 2.10.5
Fixed in:
2.10.6
Disclosed:
Nov 3, 2023

CVE-2023-47188 on NVD →

Simple Job Board <= 2.10.3 - Cross-Site Request Forgery via sjb_save_settings_section

medium

The Simple Job Board plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.3. This is due to missing or incorrect nonce validation on the sjb_save_settings_section function. This makes it possible for unauthenticated attackers to save plugin settings via a forged reques...

CVSS:
4.3
Affected:
up to 2.10.3
Fixed in:
2.10.4
Disclosed:
Apr 7, 2023

CVE-2023-29440 on NVD →

Simple Job Board [simple-job-board] < 2.10.0

unknown

[en] The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing of uploaded resumes in certain configurations.

Affected:
up to 2.10.0
Fixed in:
2.10.0
Disclosed:
Aug 22, 2022

CVE-2022-2558 on NVD →

Simple Job Board <= 2.9.6 - Information Disclosure

high

The plugin Simple Job Board for WordPress is vulnerable to Information Disclosure in versions up to, and including, 2.9.6. This makes it possible for attackers do extract sensitive information such as resumes.

CVSS:
7.5
Affected:
up to 2.9.6
Fixed in:
2.9.10
Disclosed:
Aug 1, 2022

CVE-2022-2558 on NVD →

Simple Job Board <= 2.9.3 - Local File Inclusion

high

Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php.

CVSS:
7.7
Affected:
up to 2.9.3
Fixed in:
2.9.4
Disclosed:
Feb 6, 2022

CVE-2020-35749 on NVD →

Simple Job Board <= 2.9.4 Authenticated Stored Cross-Site Scripting

medium

The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $job_board_privacy_policy_label variable echo'd out via the ~/admin/settings/class-simple-job-board-settings-privacy.php file which allowed attackers with administrative user access to inject arbitrary...

CVSS:
5.5
Affected:
up to 2.9.4
Fixed in:
2.9.5
Disclosed:
Oct 21, 2021

CVE-2021-39328 on NVD →

Simple Job Board [simple-job-board] < 2.9.5

unknown

[en] The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $job_board_privacy_policy_label variable echo'd out via the ~/admin/settings/class-simple-job-board-settings-privacy.php file which allowed attackers with administrative user access to inject arbi...

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Oct 21, 2021

CVE-2021-39328 on NVD →

Simple Job Board [simple-job-board] < 2.9.4

unknown

[en] Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php.

Affected:
up to 2.9.4
Fixed in:
2.9.4
Disclosed:
Jan 15, 2021

CVE-2020-35749 on NVD →

Simple Job Board [simple-job-board] < 2.4.4

unknown

[en] The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search.

Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Aug 13, 2019

CVE-2017-18498 on NVD →

Simple Job Board <= 2.4.4 - Reflected Cross-Site Scripting

medium

The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search.

CVSS:
6.1
Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Apr 19, 2017

CVE-2017-18498 on NVD →

Simple Job Board [simple-job-board] < 2.12.16

unknown
Affected:
up to 2.12.16
Fixed in:
2.12.16

CVE-2024-7762 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database