← Back

Wp Jobmanager

wp-jobmanager

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Job Manager
job_manager

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wp Jobmanager
1Job Manager
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with a...Show more
The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 0.7.25. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Wp Jobmanager
1Job Manager
Nov 21, 2024
Aug 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.
1Wp Jobmanager
1Job Manager
May 13, 2026
Oct 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.