Extension WordPress
Vulnérabilités WP Job Board
Cette page rassemble les failles publiées pour WP Job Board, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Job Board
10 fiches
WPJobBoard < 5.11.1 – Cross-Site Request Forgery to Remote Code Execution
The WPJobBoard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 5.11.1. This is due to missing or incorrect nonce validation on the function. This makes it possible for unauthenticated attackers to execute arbitrary…
[*, 5.11.1)
5.11.1
10/04/2025
WPJobBoard < 5.11.1 – Authenticated (Subscriber+) Path Traversal
The WP Job Board plugin for WordPress is vulnerable to Directory Traversal in all versions up to 5.11.1 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of…
[*, 5.11.1)
5.11.1
10/04/2025
WPJobBoard < 5.11.1 – Cross-Site Request Forgery
The WPJobBoard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 5.11.1. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to perform unauthorized…
[*, 5.11.1)
5.11.1
09/04/2025
WPJobBoard <= 5.10.1 – Reflected Cross-Site Scripting
The WPJobBoard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-5.10.1
5.11.1
27/01/2025
WPJobBoard <= 5.9.0 – Unauthenticated SQL Injection
The WPJobBoard plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.9.0
Non indiqué
27/06/2023
WPJobBoard <= 5.6.4 – SQL Injection
The WPJobBoard plugin for WordPress is vulnerable to SQL Injections via the 'type' and 'category' parameters in versions up to, and including, 5.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-5.6.4
5.7.0
25/11/2020
WPJobBoard <= 5.6.4 – Reflected Cross-Site Scripting & Cross-Frame Scripting
The WPJobBoard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Frame Scripting via the ‘query' and 'location’ parameters in versions up to, and including, 5.6.4 due to insufficient input sanitization and output escaping. This makes it…
*-5.6.4
5.7.0
25/11/2020
WPJobBoard <= 5.5.3 – Unauthenticated Stored Cross-Site Scripting
The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.
*-5.5.3
5.6.0
26/02/2020
WP Job Board <= 4.4.4 – SQL Injection
The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-alerts module, with a request to wp-admin/admin.php.
[*, 4.5)
4.5
06/01/2018
WPJobBoard <= 4.5.1 – Cross-Site Scripting
Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query` and `id` parameters of the `wpjb-email`, `wpjb-job`, `wpjb-application`, and `wpjb-membership` modules. Remote attackers are able…
*-4.5.1
5.0
18/08/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.