Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2021-4361

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.
Attacker Value
Unknown

CVE-2021-4352

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.
Attacker Value
Unknown

CVE-2022-1169

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
There is a XSS vulnerability in Careerfy.
Attacker Value
Unknown

CVE-2022-1168

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.
Attacker Value
Unknown

CVE-2021-24421

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue