Extension WordPress
Vulnérabilités JobSearch WP Job Board, page 2
Cette page rassemble les failles publiées pour JobSearch WP Job Board, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de JobSearch WP Job Board
34 fiches
WP JobSearch <= 2.3.3 – Authentication Bypass
The JobSearch WP Job Board plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and including, 2.3.3. This is due to the plugin not properly validating a users identity through the jobsearch_facebook_get_soc_login_url action. This…
*-2.3.3
2.3.4
24/11/2023
JobSearch WP Job Board < = 1.8.1 – Missing Authorization on jobsearch_update_job_import_schedule_call() function
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to…
*-1.8.1
1.8.2
05/10/2021
JobSearch WP Job Board <= 1.8.1 – Missing Authorization to Arbitrary Options Update
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers…
*-1.8.1
1.8.2
05/10/2021
JobSearch WP Job Board <= 1.8.1 – Missing Authorization to Settings Change
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to…
*-1.8.1
1.8.2
05/10/2021
WP JobSearch <= 1.7.3 – Stored Cross-Site Scripting
The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading…
[*, 1.7.4)
1.7.4
19/05/2021
JobSearch WP Job Board <= 1.5.5 – Reflected Cross-Site Scripting
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
[*, 1.5.6)
1.5.6
24/07/2020
JobSearch WP Job Board < 1.5.5 – Reflected Cross-Site Scripting
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
[*, 1.5.5)
1.5.5
18/07/2020
JobSearch WP Job Board <= 1.5.1 – Stored Cross-Site Scripting
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code', 'Job Title', 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', 'Full Address' fields via the candidate user profile found on the…
*-1.5.1
1.5.2
03/07/2020
JobSearch WP Job Board <= 1.5.1 – Stored Cross-Site Scripting
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Offered Salary', 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', 'Full Address' fields found on the new job listing form in versions…
*-1.5.1
1.5.2
03/07/2020
JobSearch WP Job Board <= 1.5.2 – Authenticated Stored Cross-Site Scripting
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for high-privilege attackers to inject…
[*, 1.5.3)
1.5.3
03/07/2020
JobSearch WP Job Board <= 1.5.2 – Reflected Cross-Site Scripting
The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
[*, 1.5.3)
1.5.3
03/07/2020
JobSearch WP Job Board <= 1.5.1 – Reflected Cross-Site Scripting
The JobSearch WP Job Board WordPress Plugin is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-1.5.1
1.5.2
03/07/2020
JobSearch WP Job Board <= 1.5.1 – Stored Cross-Site Scripting
The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code', 'Founded Since', 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', 'Full Address' fields via…
*-1.5.1
1.5.2
03/07/2020
WP JobSearch < 1.5.1 – Reflected Cross-Site Scripting
There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1 via search_title parameter.
[*, 1.5.1)
1.5.1
03/06/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.