JobSearch WP Job Board <= 3.2.9 - Unauthenticated Stored Cross-Site Scripting
high
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...
- CVSS:
- 7.2
- Affected:
- up to 3.2.9
- Fixed in:
- 3.3.0
- Disclosed:
- Jul 7, 2026
CVE-2026-57383 on NVD →
JobSearch WP Job Board <= 3.2.9 - Unauthenticated SQL Injection
high
The JobSearch WP Job Board plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...
- CVSS:
- 7.5
- Affected:
- up to 3.2.9
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 16, 2026
CVE-2026-54186 on NVD →
JobSearch WP Job Board <= 3.2.7 - Missing Authorization
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.2.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.8
- Disclosed:
- Jun 3, 2026
CVE-2026-49057 on NVD →
JobSearch WP Job Board <= 3.2.0 - Reflected Cross-Site Scripting
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.2
- Disclosed:
- Mar 23, 2026
CVE-2026-32493 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 3.0.8
unknown
[en] Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue affects JobSearch: from n/a through < 3.0.8.
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
- Disclosed:
- Oct 22, 2025
CVE-2025-62025 on NVD →
JobSearch < 3.0.8 - Unauthenticated PHP Object Injection
high
The JobSearch plugin for WordPress is vulnerable to PHP Object Injection in versions up to 3.0.8 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plug...
- CVSS:
- 8.1
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
- Disclosed:
- Oct 3, 2025
CVE-2025-62025 on NVD →
JobSearch < 3.0.8 - Authenticated (Subscriber+) Local File Inclusion
high
The JobSearch plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 3.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...
- CVSS:
- 7.5
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
- Disclosed:
- Aug 14, 2025
CVE-2025-52806 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] <= 2.9.0 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in eyecix JobSearch allows PHP Local File Inclusion. This issue affects JobSearch: from n/a through 2.9.0.
- Affected:
- up to 2.9.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2025
CVE-2025-52806 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] <= 2.9.0 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch allows Reflected XSS. This issue affects JobSearch: from n/a through 2.9.0.
- Affected:
- up to 2.9.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 4, 2025
CVE-2025-52798 on NVD →
JobSearch < 3.0.6 - Reflected Cross-Site Scripting
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and excluding, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...
- CVSS:
- 6.1
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- Jun 26, 2025
CVE-2025-52798 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] <= 2.9.0 (unfixed)
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobSearch: from n/a through 2.9.0.
- Affected:
- up to 2.9.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2025
CVE-2025-49978 on NVD →
JobSearch < 3.0.6 - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and excluding, 3.0.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- Jun 19, 2025
CVE-2025-49978 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] <= 2.8.8 (unfixed)
unknown
[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated...
- Affected:
- up to 2.8.8
- Fix:
- No patched version reported
- Disclosed:
- Apr 25, 2025
CVE-2024-11917 on NVD →
JobSearch WP Job Board <= 2.9.2 - Authentication Bypass via Social Logins
high
The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated attac...
- CVSS:
- 8.1
- Affected:
- up to 2.9.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2025
CVE-2024-11917 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.6.8
unknown
[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticat...
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.8
- Disclosed:
- Nov 28, 2024
CVE-2024-11925 on NVD →
WP JobSearch <= 2.6.7 - Authentication Bypass to Account Takeover and Privilege Escalation
critical
The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated at...
- CVSS:
- 9.8
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.8
- Disclosed:
- Nov 27, 2024
CVE-2024-11925 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.6.8
unknown
[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on th...
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.8
- Disclosed:
- Nov 6, 2024
CVE-2024-8615 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.6.8
unknown
[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload...
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.8
- Disclosed:
- Nov 6, 2024
CVE-2024-8614 on NVD →
WP JobSearch <= 2.6.7 - Authenticated (Subscriber+) Arbitrary File Upload
critical
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbi...
- CVSS:
- 9.9
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.8
- Disclosed:
- Nov 5, 2024
CVE-2024-8614 on NVD →
WP JobSearch <= 2.6.7 - Unauthenticated Arbitrary File Upload
critical
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the aff...
- CVSS:
- 10
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.8
- Disclosed:
- Nov 5, 2024
CVE-2024-8615 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.5.6
unknown
[en] Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
- Disclosed:
- Nov 1, 2024
CVE-2024-43929 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.5.6
unknown
[en] Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
- Disclosed:
- Nov 1, 2024
CVE-2024-43928 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.5.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- Oct 31, 2024
CVE-2024-43930 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.6.1
unknown
[en] Deserialization of Untrusted Data vulnerability in Eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.9.
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Oct 10, 2024
CVE-2024-47636 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.6.1
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in eyecix JobSearch allows Reflected XSS.This issue affects JobSearch: from n/a through 2.5.9.
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Oct 5, 2024
CVE-2024-47394 on NVD →
JobSearch <= 2.5.9 - Unauthenticated PHP Object Injection
critical
The JobSearch WP Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.9 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain...
- CVSS:
- 9.8
- Affected:
- up to 2.5.9
- Fixed in:
- 2.6.1
- Disclosed:
- Sep 30, 2024
CVE-2024-47636 on NVD →
JobSearch <= 2.5.9 - Reflected Cross-Site Scripting
medium
The JobSearch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 2.5.9
- Fixed in:
- 2.6.1
- Disclosed:
- Sep 30, 2024
CVE-2024-47394 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.5.4
unknown
[en] Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- Aug 29, 2024
CVE-2024-43931 on NVD →
JobSearch <= 2.5.3 - Unauthenticated PHP Object Injection
critical
The JobSearch WP Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain...
- CVSS:
- 10
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Aug 26, 2024
CVE-2024-43931 on NVD →
JobSearch <= 2.5.4 - Missing Authorization
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.5.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.6
- Disclosed:
- Aug 26, 2024
CVE-2024-43929 on NVD →
JobSearch <= 2.5.3 - Cross-Site Request Forgery
medium
The JobSearch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a...
- CVSS:
- 4.3
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Aug 26, 2024
CVE-2024-43930 on NVD →
JobSearch <= 2.5.4 - Missing Authorization
medium
The JobSearch plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.6
- Disclosed:
- Aug 26, 2024
CVE-2024-43928 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] <= 2.3.4 (unfixed)
unknown
[en] Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.
- Affected:
- up to 2.3.4
- Fix:
- No patched version reported
- Disclosed:
- Aug 19, 2024
CVE-2024-43245 on NVD →
JobSearch <= 2.3.4 - Authentication Bypass to Account Takeover
critical
The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.3.4. This is due to the plugin not properly validating identity on login functionality. This makes it possible for unauthenticated attackers to gain access to accounts they should not have acce...
- CVSS:
- 9.8
- Affected:
- up to 2.3.4
- Fix:
- No patched version reported
- Disclosed:
- Aug 12, 2024
CVE-2024-43245 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.3.4
unknown
[en] The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Feb 27, 2024
CVE-2023-6584 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 2.3.4
unknown
[en] The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Feb 27, 2024
CVE-2023-6585 on NVD →
WP JobSearch <= 2.3.3 - Authentication Bypass
critical
The JobSearch WP Job Board plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and including, 2.3.3. This is due to the plugin not properly validating a users identity through the jobsearch_facebook_get_soc_login_url action. This makes it possible for unauthenticated attackers to log in as...
- CVSS:
- 9.8
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Nov 24, 2023
CVE-2023-6584 on NVD →
WP JobSearch <= 2.3.3 - Unauthenticated Arbitrary File Upload
critical
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_facebook_get_soc_login_url function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sit...
- CVSS:
- 9.8
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Nov 24, 2023
CVE-2023-6585 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Jun 7, 2023
CVE-2021-4364 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Jun 7, 2023
CVE-2021-4361 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
[en] The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Jun 7, 2023
CVE-2021-4352 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.1
unknown
[en] There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.1
- Disclosed:
- Apr 4, 2022
CVE-2022-1168 on NVD →
JobSearch WP Job Board <= 1.8.1 - Missing Authorization to Arbitrary Options Update
high
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.
- CVSS:
- 8.8
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Oct 5, 2021
CVE-2021-4361 on NVD →
JobSearch WP Job Board <= 1.8.1 - Missing Authorization to Settings Change
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.
- CVSS:
- 5.3
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Oct 5, 2021
CVE-2021-4352 on NVD →
JobSearch WP Job Board < = 1.8.1 - Missing Authorization on jobsearch_update_job_import_schedule_call() function
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.
- CVSS:
- 4.3
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Oct 5, 2021
CVE-2021-4364 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Oct 5, 2021
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
Authenticated Arbitrary WordPress Options Change vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress JobSearch premium plugin (versions <= 1.8.1).
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Oct 5, 2021
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
Unauthenticated Settings Change vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress JobSearch premium plugin (versions <= 1.8.1).
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Oct 5, 2021
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Oct 5, 2021
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Oct 5, 2021
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.7.4
unknown
[en] The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Jul 12, 2021
CVE-2021-24421 on NVD →
WP JobSearch <= 1.7.3 - Stored Cross-Site Scripting
medium
The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue
- CVSS:
- 6.4
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- May 19, 2021
CVE-2021-24421 on NVD →
JobSearch WP Job Board <= 1.5.5 - Reflected Cross-Site Scripting
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Jul 24, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.6
unknown
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Jul 24, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.6
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress JobSearch premium plugin (versions <= 1.5.5).
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Jul 24, 2020
JobSearch WP Job Board < 1.5.5 - Reflected Cross-Site Scripting
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Jul 18, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.5
unknown
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Jul 18, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.5
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress JobSearch premium plugin (versions <= 1.5.4).
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Jul 18, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3
unknown
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability (job pages) discovered by m0ze in WordPress JobSearch premium plugin (versions <= 1.5.2).
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 5, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress JobSearch premium plugin (versions <= 1.5.2).
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 5, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3
unknown
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability (profile pages) discovered by m0ze in WordPress JobSearch premium plugin (versions <= 1.5.2).
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 5, 2020
JobSearch WP Job Board <= 1.5.1 - Stored Cross-Site Scripting
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code', 'Founded Since', 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', 'Full Address' fields via the user dashboard employer form...
- CVSS:
- 6.4
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board <= 1.5.2 - Authenticated Stored Cross-Site Scripting
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for high-privilege attackers to inject arbitrary web scripts in pages that will execute whenever a user...
- CVSS:
- 6.4
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board <= 1.5.1 - Stored Cross-Site Scripting
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Offered Salary', 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', 'Full Address' fields found on the new job listing form in versions up to, and including, 1.5.1 due to insuffici...
- CVSS:
- 6.4
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board <= 1.5.1 - Stored Cross-Site Scripting
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code', 'Job Title', 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', 'Full Address' fields via the candidate user profile found on the user dashboard in versions up to, and including, 1.5.1 due to...
- CVSS:
- 6.4
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board <= 1.5.1 - Reflected Cross-Site Scripting
medium
The JobSearch WP Job Board WordPress Plugin is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board <= 1.5.2 - Reflected Cross-Site Scripting
medium
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3
unknown
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3
unknown
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for high-privilege attackers to inject arbitrary web scripts in pages that will execute whenever a user...
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.2
unknown
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Offered Salary', 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', 'Full Address' fields found on the new job listing form in versions up to, and including, 1.5.1 due to insuffici...
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.2
unknown
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code', 'Job Title', 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', 'Full Address' fields via the candidate user profile found on the user dashboard in versions up to, and including, 1.5.1 due to...
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.2
unknown
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code', 'Founded Since', 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', 'Full Address' fields via the user dashboard employer form...
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Jul 3, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.2
unknown
The JobSearch WP Job Board WordPress Plugin is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Jul 3, 2020
WP JobSearch < 1.5.1 - Reflected Cross-Site Scripting
high
There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1 via search_title parameter.
- CVSS:
- 7.1
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.1
- Disclosed:
- Jun 3, 2020
CVE-2022-1168 on NVD →
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.1
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by Daniel Ruf in WordPress JobSearch premium plugin (versions <= 1.5.0).
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.1
- Disclosed:
- Jun 3, 2020
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.5
unknown
An Unauthenticated Reflected XSS vulnerability was discovered in the JobSearch plugin v1.5.4 for WordPress.
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.3
unknown
An Unauthenticated Reflected & Multiple Authenticated Persistent XSS vulnerabilities was discovered in the JobSearch plugin through 1.5.1 and 1.5.2 for WordPress.
Authenticated Persistent XSS on the Candidate and Employer Profile pages.
An Authenticated Persistent XSS @ Job Page will trigger on the dashboard...
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
The jobsearch_add_job_import_schedule_call and jobsearch_update_job_import_schedule_call AJAx action o the plugin, available to any authenticated user do not have authorisation and CSRF check sin place, allowing users with a role as low as subscriber to call them
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
The jobsearch_job_integrations_settin_save AJAX action of the plugin, available to any authenticated user, does not have authorisation and CSRF in place, allowing any authenticated user, such as subscriber to call it and modify arbitrary blog options
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.8.2
unknown
The save_locsettings function, hooked to the init action (which will therefore run each time the blog is loaded) could allow unauthenticated users to modify the plugin's settings
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
JobSearch WP Job Board WordPress Plugin [wp-jobsearch] < 1.5.6
unknown
An Unauthenticated Reflected XSS vulnerability was discovered in the JobSearch plugin v1.5.5 for WordPress.
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6