WorkScout-Core <= 1.7.08 - Cross-Site Request Forgery
medium
The WorkScout-Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.08. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can t...
- CVSS:
- 4.3
- Affected:
- up to 1.7.08
- Fix:
- No patched version reported
- Disclosed:
- Jul 2, 2026
CVE-2026-57786 on NVD →
Workscout Core <= 1.7.11 - Unauthenticated Arbitrary File Deletion
critical
The Workscout Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 1.7.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the ri...
- CVSS:
- 9.1
- Affected:
- up to 1.7.11
- Fixed in:
- 1.7.12
- Disclosed:
- Jun 15, 2026
CVE-2026-52716 on NVD →
WorkScout-Core <= 1.7.06 - Unauthenticated Stored Cross-Site Scripting
high
The WorkScout-Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user access...
- CVSS:
- 7.2
- Affected:
- up to 1.7.06
- Fixed in:
- 1.7.07
- Disclosed:
- Jan 21, 2026
CVE-2025-67960 on NVD →
WorkScout-Core < 1.7.06 - Reflected Cross-Site Scripting
medium
The WorkScout-Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.7.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user in...
- CVSS:
- 6.1
- Affected:
- up to 1.7.06
- Fixed in:
- 1.7.06
- Disclosed:
- Sep 23, 2025
CVE-2025-59571 on NVD →
WorkScout-Core < 1.7.06 - Cross-Site Request Forgery
medium
The Workscout Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 1.7.06 (exclusive). This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administr...
- CVSS:
- 4.3
- Affected:
- up to 1.7.06
- Fixed in:
- 1.7.06
- Disclosed:
- Sep 22, 2025
CVE-2025-59572 on NVD →
WorkScout - Job Board WordPress Theme <= 2.0.31 - Stored Cross-Site Scripting
medium
The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues
- CVSS:
- 6.4
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Apr 8, 2021
CVE-2021-24246 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database