WP Job Manager <= 2.4.0 - Missing Authorization
medium
The WP Job Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.1
- Disclosed:
- Jan 29, 2026
CVE-2026-25404 on NVD →
WP Job Manager <= 2.2.2 - Unauthenticated Information Exposure
medium
The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.2.2
- Fixed in:
- 2.3.0
- Disclosed:
- May 7, 2024
CVE-2024-34549 on NVD →
WP Job Manager <= 2.0.0 - Missing Authorization
medium
The WP Job Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rest route associated with the update_job_status function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to update job statuses.
- CVSS:
- 5.3
- Affected:
- up to 2.0.0
- Fixed in:
- 2.1.0
- Disclosed:
- Jan 5, 2024
CVE-2023-52211 on NVD →
WP Job Manager <= 2.0.0 - Cross-Site Request Forgery
medium
The WP Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation on the settings_save() function. This makes it possible for unauthenticated attackers to save settings via a forged request granted they can t...
- CVSS:
- 4.3
- Affected:
- up to 2.0.0
- Fixed in:
- 2.1.0
- Disclosed:
- Jan 5, 2024
CVE-2023-52212 on NVD →
WP Job Manager <= 1.31.2 - PHP Object Injection via PHAR Deserialization
high
TheWP Job Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.31.2 via deserialization of user-controlled input allowing a phar wrapper. This allows attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via...
- CVSS:
- 7.5
- Affected:
- up to 1.31.3
- Fixed in:
- 1.31.3
- Disclosed:
- Jan 7, 2019
WP Job Manager <= 1.29.2 - PHP Object Injection
critical
The WP Job Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.29.2 via deserialization of untrusted input in the get_job_listings function. This allows unauthorized attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to implement...
- CVSS:
- 9.8
- Affected:
- up to 1.29.2
- Fixed in:
- 1.29.3
- Disclosed:
- Mar 2, 2018
WP Job Manager <= 1.26.1 - Arbitrary File Upload
high
The WP Job Manager plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the via the ~/class-wp-job-manager-ajax.php file in versions up to, and including, 1.26.1. This makes it possible for unauthenticated attackers to upload arbitrary files...
- CVSS:
- 8.8
- Affected:
- up to 1.26.2
- Fixed in:
- 1.26.2
- Disclosed:
- Jul 11, 2016
WP Job Manager < 1.23.8 - Multiple Cross-Site Scripting
medium
The WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘create_account_email' and 'create_account_username’ parameters in versions up to, and including, 1.23.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj...
- CVSS:
- 5.4
- Affected:
- up to 1.23.8
- Fixed in:
- 1.23.8
- Disclosed:
- Aug 20, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database