theme

Careerfy Vulnerabilities

26 known security issues reported for the Careerfy WordPress theme. Most recent disclosed Jun 9, 2023.

2 high 7 medium

Running Careerfy on your site? Check whether your installed version is affected.

Scan your site free

Careerfy [careerfy] < 6.3.0

unknown

Update the WordPress Careerfy premium theme to the latest available version (at least 6.3.0). Vlad Vector discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Careerfy Theme. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML p...

Affected:
up to 6.3.0
Fixed in:
6.3.0
Disclosed:
Jun 9, 2023

Careerfy [careerfy] < 3.9.0

unknown

[en] There is a XSS vulnerability in Careerfy.

Affected:
up to 3.9.0
Fixed in:
3.9.0
Disclosed:
Apr 4, 2022

CVE-2022-1169 on NVD →

Careerfy <= 7.0 - Cross-Site Request Forgery and Missing Authorization

medium

The Careerfy theme for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 7.0. This is due to missing nonce validation and capability checks on several functions. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber...

CVSS:
6.3
Affected:
up to 7.0
Fixed in:
7.1.0
Disclosed:
Sep 24, 2021

Careerfy [careerfy] < 7.1.0

unknown

The Careerfy theme for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 7.0. This is due to missing nonce validation and capability checks on several functions. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber...

Affected:
up to 7.1.0
Fixed in:
7.1.0
Disclosed:
Sep 24, 2021

Careerfy [careerfy] < 4.4.0

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Careerfy premium theme (versions <= 4.3.0).

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Jul 24, 2020

Careerfy <= 4.3.0 - Reflected Cross-Site Scripting

high

The Careerfy for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing...

CVSS:
7.1
Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Jul 22, 2020

Careerfy [careerfy] < 4.4.0

unknown

The Careerfy for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing...

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Jul 22, 2020

Careerfy <= 4.2.0 - Reflected Cross-Site Scripting

medium

The Careerfy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

CVSS:
6.1
Affected:
up to 4.2.0
Fixed in:
4.3.0
Disclosed:
Jul 18, 2020

Careerfy [careerfy] < 4.3.0

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Careerfy premium theme (versions <= 4.2.0).

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Jul 18, 2020

Careerfy [careerfy] < 4.3.0

unknown

The Careerfy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Jul 18, 2020

Careerfy <= 4.0.0 - Cross-Site Scripting

high

The Careerfy theme for WordPress is vulnerable to Multiple Cross-Site Scripting in versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.2
Affected:
up to 4.0.0
Fixed in:
4.1.0
Disclosed:
Jul 5, 2020

Careerfy [careerfy] < 4.1.0

unknown

Multiple Cross-Site Scripting (XSS) vulnerabilities discovered by m0ze in WordPress Careerfy premium theme (versions <= 4.0.0).

Affected:
up to 4.1.0
Fixed in:
4.1.0
Disclosed:
Jul 5, 2020

Careerfy [careerfy] < 4.1.0

unknown

The Careerfy theme for WordPress is vulnerable to Multiple Cross-Site Scripting in versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 4.1.0
Fixed in:
4.1.0
Disclosed:
Jul 5, 2020

Careerfy - Job Board WordPress Theme <= 3.9.0 - Authenticated Stored Cross-Site Scripting

medium

The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficient input sanitization and output e...

CVSS:
6.4
Affected:
up to 3.9.0
Fixed in:
4.0.0
Disclosed:
Jul 1, 2020

Careerfy - Job Board WordPress Theme <= 3.9.0 - Authenticated Stored Cross-Site Scripting

medium

The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible...

CVSS:
6.4
Affected:
up to 3.9.0
Fixed in:
4.0.0
Disclosed:
Jul 1, 2020

Careerfy - Job Board WordPress Theme <= 3.9.0 - Authenticated Stored Cross-Site Scripting

medium

The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficien...

CVSS:
6.4
Affected:
up to 3.9.0
Fixed in:
4.0.0
Disclosed:
Jul 1, 2020

Careerfy - Job Board WordPress Theme <= 3.9.0 - Reflected Cross-Site Scripting

medium

The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

CVSS:
6.1
Affected:
up to 3.9.0
Fixed in:
4.0.0
Disclosed:
Jul 1, 2020

Careerfy [careerfy] < 4.0.0

unknown

The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficient input sanitization and output e...

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Jul 1, 2020

Careerfy [careerfy] < 4.0.0

unknown

The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficien...

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Jul 1, 2020

Careerfy [careerfy] < 4.0.0

unknown

The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible...

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Jul 1, 2020

Careerfy [careerfy] < 4.0.0

unknown

The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Jul 1, 2020

Careerfy < 3.9.0 - Cross-Site Scripting

medium

The Careerfy theme plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 3.9.0
Fixed in:
3.9.0
Disclosed:
Jun 3, 2020

CVE-2022-1169 on NVD →

Careerfy [careerfy] < 3.9.0

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by Daniel Ruf in WordPress Careerfy premium theme (versions <= 3.8.0).

Affected:
up to 3.9.0
Fixed in:
3.9.0
Disclosed:
Jun 3, 2020

Careerfy [careerfy] < 4.1.0

unknown

An Unauthenticated Reflected &amp; Multiple Authenticated Persistent XSS vulnerabilities was discovered in the Careerfy Job Board theme through 3.9.0 and 4.0.0 for WordPress. Authenticated Persistent XSS on the Candidate and Employer Profile pages. An Authenticated Persistent XSS @ Job Page will trigger on the da...

Affected:
up to 4.1.0
Fixed in:
4.1.0

Careerfy [careerfy] < 4.3.0

unknown

An Unauthenticated Reflected XSS vulnerability was discovered in the Careerfy Job Board theme v4.2.0 for WordPress.

Affected:
up to 4.3.0
Fixed in:
4.3.0

Careerfy [careerfy] < 4.4.0

unknown

An Unauthenticated Reflected XSS vulnerability was discovered in the Careerfy Job Board theme v4.3.0 for WordPress.

Affected:
up to 4.4.0
Fixed in:
4.4.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database