Extension WordPress
Vulnérabilités JobCareer | Job Board Responsive WordPress Theme
Cette page rassemble les failles publiées pour JobCareer | Job Board Responsive WordPress Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de JobCareer | Job Board Responsive WordPress Theme
6 fiches
JobCareer | Job Board Responsive WordPress Theme <= 7.1 – Missing Authorization to Authenticated (Subscriber+) Multiple Administrative Actions
The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 7.1.…
*-7.1
Non indiqué
13/03/2025
JobCareer <= 3.4 – Cross-Site Scripting
The JobCareer plugin for WordPress is vulnerable to Cross-Site Scripting via the 'job_title', 'specialisms', and 'location' parameters and address textfield in versions up to, and including, 3.4 due to insufficient input sanitization and output escaping. This makes it…
*-3.4
3.5
24/07/2020
JobCareer <= 3.4 – Multiple Cross-Site Scripting
The JobCareer | Job Board Responsive plugin for WordPress is vulnerable to both authenticated Stored and unauthenticated Reflected Cross-Site Scripting in versions up to, and including, 3.4 due to insufficient input sanitization and output escaping. The Reflected XSS…
*-3.4
3.5
24/07/2020
JobCareer | Job Board Responsive WordPress Theme <= 2.5.1 – Stored Cross-Site Scripting
The JobCareer theme before 2.5.1 for WordPress has stored XSS.
[*, 2.5.1)
2.5.1
24/04/2019
JobCareer | Job Board Responsive WordPress Theme < 2.4 – Unauthenticated Arbitrary Password Reset
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's account.
[*, 2.4.1)
2.4.1
04/12/2018
JobCareer | Job Board Responsive WordPress Theme < 2.4 – User Enumeration
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.
*-2.4
2.4.1
04/12/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.