plugin

Wp Jobsearch Vulnerabilities

81 known security issues reported for the Wp Jobsearch WordPress plugin. Most recent disclosed Jul 7, 2026.

8 critical 7 high 19 medium

Running Wp Jobsearch on your site? Check whether your installed version is affected.

Scan your site free

JobSearch WP Job Board <= 3.2.9 - Unauthenticated Stored Cross-Site Scripting

high

The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
7.2
Affected:
up to 3.2.9
Fixed in:
3.3.0
Disclosed:
Jul 7, 2026

CVE-2026-57383 on NVD →

JobSearch WP Job Board <= 3.2.9 - Unauthenticated SQL Injection

high

The JobSearch WP Job Board plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...

CVSS:
7.5
Affected:
up to 3.2.9
Fixed in:
3.3.0
Disclosed:
Jun 16, 2026

CVE-2026-54186 on NVD →

JobSearch WP Job Board <= 3.2.7 - Missing Authorization

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.2.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.2.7
Fixed in:
3.2.8
Disclosed:
Jun 3, 2026

CVE-2026-49057 on NVD →

JobSearch WP Job Board <= 3.2.0 - Reflected Cross-Site Scripting

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 3.2.0
Fixed in:
3.2.2
Disclosed:
Mar 23, 2026

CVE-2026-32493 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 3.0.8

unknown

[en] Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue affects JobSearch: from n/a through < 3.0.8.

Affected:
up to 3.0.8
Fixed in:
3.0.8
Disclosed:
Oct 22, 2025

CVE-2025-62025 on NVD →

JobSearch < 3.0.8 - Unauthenticated PHP Object Injection

high

The JobSearch plugin for WordPress is vulnerable to PHP Object Injection in versions up to 3.0.8 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plug...

CVSS:
8.1
Affected:
up to 3.0.8
Fixed in:
3.0.8
Disclosed:
Oct 3, 2025

CVE-2025-62025 on NVD →

JobSearch < 3.0.8 - Authenticated (Subscriber+) Local File Inclusion

high

The JobSearch plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 3.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...

CVSS:
7.5
Affected:
up to 3.0.8
Fixed in:
3.0.8
Disclosed:
Aug 14, 2025

CVE-2025-52806 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] <= 2.9.0 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in eyecix JobSearch allows PHP Local File Inclusion. This issue affects JobSearch: from n/a through 2.9.0.

Affected:
up to 2.9.0
Fix:
No patched version reported
Disclosed:
Aug 14, 2025

CVE-2025-52806 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] <= 2.9.0 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch allows Reflected XSS. This issue affects JobSearch: from n/a through 2.9.0.

Affected:
up to 2.9.0
Fix:
No patched version reported
Disclosed:
Jul 4, 2025

CVE-2025-52798 on NVD →

JobSearch < 3.0.6 - Reflected Cross-Site Scripting

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and excluding, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...

CVSS:
6.1
Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Jun 26, 2025

CVE-2025-52798 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] <= 2.9.0 (unfixed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobSearch: from n/a through 2.9.0.

Affected:
up to 2.9.0
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-49978 on NVD →

JobSearch < 3.0.6 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and excluding, 3.0.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Jun 19, 2025

CVE-2025-49978 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] <= 2.8.8 (unfixed)

unknown

[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated...

Affected:
up to 2.8.8
Fix:
No patched version reported
Disclosed:
Apr 25, 2025

CVE-2024-11917 on NVD →

JobSearch WP Job Board <= 2.9.2 - Authentication Bypass via Social Logins

high

The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated attac...

CVSS:
8.1
Affected:
up to 2.9.2
Fix:
No patched version reported
Disclosed:
Apr 24, 2025

CVE-2024-11917 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.6.8

unknown

[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticat...

Affected:
up to 2.6.8
Fixed in:
2.6.8
Disclosed:
Nov 28, 2024

CVE-2024-11925 on NVD →

WP JobSearch <= 2.6.7 - Authentication Bypass to Account Takeover and Privilege Escalation

critical

The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated at...

CVSS:
9.8
Affected:
up to 2.6.7
Fixed in:
2.6.8
Disclosed:
Nov 27, 2024

CVE-2024-11925 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.6.8

unknown

[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on th...

Affected:
up to 2.6.8
Fixed in:
2.6.8
Disclosed:
Nov 6, 2024

CVE-2024-8615 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.6.8

unknown

[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload...

Affected:
up to 2.6.8
Fixed in:
2.6.8
Disclosed:
Nov 6, 2024

CVE-2024-8614 on NVD →

WP JobSearch <= 2.6.7 - Authenticated (Subscriber+) Arbitrary File Upload

critical

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbi...

CVSS:
9.9
Affected:
up to 2.6.7
Fixed in:
2.6.8
Disclosed:
Nov 5, 2024

CVE-2024-8614 on NVD →

WP JobSearch <= 2.6.7 - Unauthenticated Arbitrary File Upload

critical

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the aff...

CVSS:
10
Affected:
up to 2.6.7
Fixed in:
2.6.8
Disclosed:
Nov 5, 2024

CVE-2024-8615 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.5.6

unknown

[en] Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.

Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Nov 1, 2024

CVE-2024-43929 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.5.6

unknown

[en] Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.

Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Nov 1, 2024

CVE-2024-43928 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.5.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.

Affected:
up to 2.5.4
Fixed in:
2.5.4
Disclosed:
Oct 31, 2024

CVE-2024-43930 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.6.1

unknown

[en] Deserialization of Untrusted Data vulnerability in Eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.9.

Affected:
up to 2.6.1
Fixed in:
2.6.1
Disclosed:
Oct 10, 2024

CVE-2024-47636 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.6.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in eyecix JobSearch allows Reflected XSS.This issue affects JobSearch: from n/a through 2.5.9.

Affected:
up to 2.6.1
Fixed in:
2.6.1
Disclosed:
Oct 5, 2024

CVE-2024-47394 on NVD →

JobSearch <= 2.5.9 - Unauthenticated PHP Object Injection

critical

The JobSearch WP Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.9 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain...

CVSS:
9.8
Affected:
up to 2.5.9
Fixed in:
2.6.1
Disclosed:
Sep 30, 2024

CVE-2024-47636 on NVD →

JobSearch <= 2.5.9 - Reflected Cross-Site Scripting

medium

The JobSearch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 2.5.9
Fixed in:
2.6.1
Disclosed:
Sep 30, 2024

CVE-2024-47394 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.5.4

unknown

[en] Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.

Affected:
up to 2.5.4
Fixed in:
2.5.4
Disclosed:
Aug 29, 2024

CVE-2024-43931 on NVD →

JobSearch <= 2.5.3 - Unauthenticated PHP Object Injection

critical

The JobSearch WP Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain...

CVSS:
10
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
Aug 26, 2024

CVE-2024-43931 on NVD →

JobSearch <= 2.5.4 - Missing Authorization

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.5.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.5.4
Fixed in:
2.5.6
Disclosed:
Aug 26, 2024

CVE-2024-43929 on NVD →

JobSearch <= 2.5.3 - Cross-Site Request Forgery

medium

The JobSearch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a...

CVSS:
4.3
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
Aug 26, 2024

CVE-2024-43930 on NVD →

JobSearch <= 2.5.4 - Missing Authorization

medium

The JobSearch plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.5.4
Fixed in:
2.5.6
Disclosed:
Aug 26, 2024

CVE-2024-43928 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] <= 2.3.4 (unfixed)

unknown

[en] Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.

Affected:
up to 2.3.4
Fix:
No patched version reported
Disclosed:
Aug 19, 2024

CVE-2024-43245 on NVD →

JobSearch <= 2.3.4 - Authentication Bypass to Account Takeover

critical

The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.3.4. This is due to the plugin not properly validating identity on login functionality. This makes it possible for unauthenticated attackers to gain access to accounts they should not have acce...

CVSS:
9.8
Affected:
up to 2.3.4
Fix:
No patched version reported
Disclosed:
Aug 12, 2024

CVE-2024-43245 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.3.4

unknown

[en] The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Feb 27, 2024

CVE-2023-6584 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.3.4

unknown

[en] The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Feb 27, 2024

CVE-2023-6585 on NVD →

WP JobSearch <= 2.3.3 - Authentication Bypass

critical

The JobSearch WP Job Board plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and including, 2.3.3. This is due to the plugin not properly validating a users identity through the jobsearch_facebook_get_soc_login_url action. This makes it possible for unauthenticated attackers to log in as...

CVSS:
9.8
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Nov 24, 2023

CVE-2023-6584 on NVD →

WP JobSearch <= 2.3.3 - Unauthenticated Arbitrary File Upload

critical

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_facebook_get_soc_login_url function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sit...

CVSS:
9.8
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Nov 24, 2023

CVE-2023-6585 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Jun 7, 2023

CVE-2021-4364 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Jun 7, 2023

CVE-2021-4361 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Jun 7, 2023

CVE-2021-4352 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.1

unknown

[en] There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.

Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Apr 4, 2022

CVE-2022-1168 on NVD →

JobSearch WP Job Board <= 1.8.1 - Missing Authorization to Arbitrary Options Update

high

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.

CVSS:
8.8
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Oct 5, 2021

CVE-2021-4361 on NVD →

JobSearch WP Job Board <= 1.8.1 - Missing Authorization to Settings Change

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.

CVSS:
5.3
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Oct 5, 2021

CVE-2021-4352 on NVD →

JobSearch WP Job Board < = 1.8.1 - Missing Authorization on jobsearch_update_job_import_schedule_call() function

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.

CVSS:
4.3
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Oct 5, 2021

CVE-2021-4364 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Oct 5, 2021

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

Authenticated Arbitrary WordPress Options Change vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress JobSearch premium plugin (versions <= 1.8.1).

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Oct 5, 2021

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

Unauthenticated Settings Change vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress JobSearch premium plugin (versions <= 1.8.1).

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Oct 5, 2021

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Oct 5, 2021

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Oct 5, 2021

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.7.4

unknown

[en] The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue

Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
Jul 12, 2021

CVE-2021-24421 on NVD →

WP JobSearch <= 1.7.3 - Stored Cross-Site Scripting

medium

The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue

CVSS:
6.4
Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
May 19, 2021

CVE-2021-24421 on NVD →

JobSearch WP Job Board <= 1.5.5 - Reflected Cross-Site Scripting

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Jul 24, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.6

unknown

The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Jul 24, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.6

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress JobSearch premium plugin (versions <= 1.5.5).

Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Jul 24, 2020

JobSearch WP Job Board < 1.5.5 - Reflected Cross-Site Scripting

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Jul 18, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.5

unknown

The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Jul 18, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.5

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress JobSearch premium plugin (versions <= 1.5.4).

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Jul 18, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability (job pages) discovered by m0ze in WordPress JobSearch premium plugin (versions <= 1.5.2).

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Jul 5, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress JobSearch premium plugin (versions <= 1.5.2).

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Jul 5, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability (profile pages) discovered by m0ze in WordPress JobSearch premium plugin (versions <= 1.5.2).

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Jul 5, 2020

JobSearch WP Job Board <= 1.5.1 - Stored Cross-Site Scripting

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code', 'Founded Since', 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', 'Full Address' fields via the user dashboard employer form...

CVSS:
6.4
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Jul 3, 2020

JobSearch WP Job Board <= 1.5.2 - Authenticated Stored Cross-Site Scripting

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for high-privilege attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
6.4
Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Jul 3, 2020

JobSearch WP Job Board <= 1.5.1 - Stored Cross-Site Scripting

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Offered Salary', 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', 'Full Address' fields found on the new job listing form in versions up to, and including, 1.5.1 due to insuffici...

CVSS:
6.4
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Jul 3, 2020

JobSearch WP Job Board <= 1.5.1 - Stored Cross-Site Scripting

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code', 'Job Title', 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', 'Full Address' fields via the candidate user profile found on the user dashboard in versions up to, and including, 1.5.1 due to...

CVSS:
6.4
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Jul 3, 2020

JobSearch WP Job Board <= 1.5.1 - Reflected Cross-Site Scripting

medium

The JobSearch WP Job Board WordPress Plugin is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Jul 3, 2020

JobSearch WP Job Board <= 1.5.2 - Reflected Cross-Site Scripting

medium

The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Jul 3, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3

unknown

The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Jul 3, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3

unknown

The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for high-privilege attackers to inject arbitrary web scripts in pages that will execute whenever a user...

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Jul 3, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.2

unknown

The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Offered Salary', 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', 'Full Address' fields found on the new job listing form in versions up to, and including, 1.5.1 due to insuffici...

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Jul 3, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.2

unknown

The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code', 'Job Title', 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', 'Full Address' fields via the candidate user profile found on the user dashboard in versions up to, and including, 1.5.1 due to...

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Jul 3, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.2

unknown

The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code', 'Founded Since', 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', 'Full Address' fields via the user dashboard employer form...

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Jul 3, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.2

unknown

The JobSearch WP Job Board WordPress Plugin is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Jul 3, 2020

WP JobSearch < 1.5.1 - Reflected Cross-Site Scripting

high

There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1 via search_title parameter.

CVSS:
7.1
Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Jun 3, 2020

CVE-2022-1168 on NVD →

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.1

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by Daniel Ruf in WordPress JobSearch premium plugin (versions <= 1.5.0).

Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Jun 3, 2020

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.5

unknown

An Unauthenticated Reflected XSS vulnerability was discovered in the JobSearch plugin v1.5.4 for WordPress.

Affected:
up to 1.5.5
Fixed in:
1.5.5

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3

unknown

An Unauthenticated Reflected &amp; Multiple Authenticated Persistent XSS vulnerabilities was discovered in the JobSearch plugin through 1.5.1 and 1.5.2 for WordPress. Authenticated Persistent XSS on the Candidate and Employer Profile pages. An Authenticated Persistent XSS @ Job Page will trigger on the dashboard...

Affected:
up to 1.5.3
Fixed in:
1.5.3

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

The jobsearch_add_job_import_schedule_call and jobsearch_update_job_import_schedule_call AJAx action o the plugin, available to any authenticated user do not have authorisation and CSRF check sin place, allowing users with a role as low as subscriber to call them

Affected:
up to 1.8.2
Fixed in:
1.8.2

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

The jobsearch_job_integrations_settin_save AJAX action of the plugin, available to any authenticated user, does not have authorisation and CSRF in place, allowing any authenticated user, such as subscriber to call it and modify arbitrary blog options

Affected:
up to 1.8.2
Fixed in:
1.8.2

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2

unknown

The save_locsettings function, hooked to the init action (which will therefore run each time the blog is loaded) could allow unauthenticated users to modify the plugin&#039;s settings

Affected:
up to 1.8.2
Fixed in:
1.8.2

JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.6

unknown

An Unauthenticated Reflected XSS vulnerability was discovered in the JobSearch plugin v1.5.5 for WordPress.

Affected:
up to 1.5.6
Fixed in:
1.5.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database