Careerfy [careerfy] < 6.3.0
unknown
Update the WordPress Careerfy premium theme to the latest available version (at least 6.3.0).
Vlad Vector discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Careerfy Theme. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML p...
- Affected:
- up to 6.3.0
- Fixed in:
- 6.3.0
- Disclosed:
- Jun 9, 2023
Careerfy [careerfy] < 3.9.0
unknown
[en] There is a XSS vulnerability in Careerfy.
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.0
- Disclosed:
- Apr 4, 2022
CVE-2022-1169 on NVD →
Careerfy <= 7.0 - Cross-Site Request Forgery and Missing Authorization
medium
The Careerfy theme for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 7.0. This is due to missing nonce validation and capability checks on several functions. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber...
- CVSS:
- 6.3
- Affected:
- up to 7.0
- Fixed in:
- 7.1.0
- Disclosed:
- Sep 24, 2021
Careerfy [careerfy] < 7.1.0
unknown
The Careerfy theme for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 7.0. This is due to missing nonce validation and capability checks on several functions. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber...
- Affected:
- up to 7.1.0
- Fixed in:
- 7.1.0
- Disclosed:
- Sep 24, 2021
Careerfy [careerfy] < 4.4.0
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Careerfy premium theme (versions <= 4.3.0).
- Affected:
- up to 4.4.0
- Fixed in:
- 4.4.0
- Disclosed:
- Jul 24, 2020
Careerfy <= 4.3.0 - Reflected Cross-Site Scripting
high
The Careerfy for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing...
- CVSS:
- 7.1
- Affected:
- up to 4.4.0
- Fixed in:
- 4.4.0
- Disclosed:
- Jul 22, 2020
Careerfy [careerfy] < 4.4.0
unknown
The Careerfy for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing...
- Affected:
- up to 4.4.0
- Fixed in:
- 4.4.0
- Disclosed:
- Jul 22, 2020
Careerfy <= 4.2.0 - Reflected Cross-Site Scripting
medium
The Careerfy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- CVSS:
- 6.1
- Affected:
- up to 4.2.0
- Fixed in:
- 4.3.0
- Disclosed:
- Jul 18, 2020
Careerfy [careerfy] < 4.3.0
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Careerfy premium theme (versions <= 4.2.0).
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
- Disclosed:
- Jul 18, 2020
Careerfy [careerfy] < 4.3.0
unknown
The Careerfy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
- Disclosed:
- Jul 18, 2020
Careerfy <= 4.0.0 - Cross-Site Scripting
high
The Careerfy theme for WordPress is vulnerable to Multiple Cross-Site Scripting in versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.2
- Affected:
- up to 4.0.0
- Fixed in:
- 4.1.0
- Disclosed:
- Jul 5, 2020
Careerfy [careerfy] < 4.1.0
unknown
Multiple Cross-Site Scripting (XSS) vulnerabilities discovered by m0ze in WordPress Careerfy premium theme (versions <= 4.0.0).
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Jul 5, 2020
Careerfy [careerfy] < 4.1.0
unknown
The Careerfy theme for WordPress is vulnerable to Multiple Cross-Site Scripting in versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Jul 5, 2020
Careerfy - Job Board WordPress Theme <= 3.9.0 - Authenticated Stored Cross-Site Scripting
medium
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficient input sanitization and output e...
- CVSS:
- 6.4
- Affected:
- up to 3.9.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 1, 2020
Careerfy - Job Board WordPress Theme <= 3.9.0 - Authenticated Stored Cross-Site Scripting
medium
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible...
- CVSS:
- 6.4
- Affected:
- up to 3.9.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 1, 2020
Careerfy - Job Board WordPress Theme <= 3.9.0 - Authenticated Stored Cross-Site Scripting
medium
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficien...
- CVSS:
- 6.4
- Affected:
- up to 3.9.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 1, 2020
Careerfy - Job Board WordPress Theme <= 3.9.0 - Reflected Cross-Site Scripting
medium
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- CVSS:
- 6.1
- Affected:
- up to 3.9.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 1, 2020
Careerfy [careerfy] < 4.0.0
unknown
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficient input sanitization and output e...
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 1, 2020
Careerfy [careerfy] < 4.0.0
unknown
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficien...
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 1, 2020
Careerfy [careerfy] < 4.0.0
unknown
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible...
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 1, 2020
Careerfy [careerfy] < 4.0.0
unknown
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 1, 2020
Careerfy < 3.9.0 - Cross-Site Scripting
medium
The Careerfy theme plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.0
- Disclosed:
- Jun 3, 2020
CVE-2022-1169 on NVD →
Careerfy [careerfy] < 3.9.0
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by Daniel Ruf in WordPress Careerfy premium theme (versions <= 3.8.0).
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.0
- Disclosed:
- Jun 3, 2020
Careerfy [careerfy] < 4.1.0
unknown
An Unauthenticated Reflected & Multiple Authenticated Persistent XSS vulnerabilities was discovered in the Careerfy Job Board theme through 3.9.0 and 4.0.0 for WordPress.
Authenticated Persistent XSS on the Candidate and Employer Profile pages.
An Authenticated Persistent XSS @ Job Page will trigger on the da...
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
Careerfy [careerfy] < 4.3.0
unknown
An Unauthenticated Reflected XSS vulnerability was discovered in the Careerfy Job Board theme v4.2.0 for WordPress.
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
Careerfy [careerfy] < 4.4.0
unknown
An Unauthenticated Reflected XSS vulnerability was discovered in the Careerfy Job Board theme v4.3.0 for WordPress.
- Affected:
- up to 4.4.0
- Fixed in:
- 4.4.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database