Vulnerabilities > Wpjobportal

DATE CVE VULNERABILITY TITLE RISK
2024-09-04 CVE-2024-7950 Missing Authorization vulnerability in Wpjobportal WP JOB Portal
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary Settings Update, and User Creation in all versions up to, and including, 2.1.6 via several functions called by the 'checkFormRequest' function.
network
low complexity
wpjobportal CWE-862
critical
9.8
2024-06-21 CVE-2024-35759 Cross-site Scripting vulnerability in Wpjobportal WP JOB Portal
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Job Portal allows Stored XSS.This issue affects WP Job Portal: from n/a through 2.1.3.
network
low complexity
wpjobportal CWE-79
4.8
2024-06-21 CVE-2024-35760 Cross-site Scripting vulnerability in Wpjobportal WP JOB Portal
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Job Portal allows Stored XSS.This issue affects WP Job Portal: from n/a through 2.1.3.
network
low complexity
wpjobportal CWE-79
4.8
2024-01-17 CVE-2022-41786 Missing Authorization vulnerability in Wpjobportal WP JOB Portal
Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.1.
network
low complexity
wpjobportal CWE-862
critical
9.8
2024-01-05 CVE-2023-52184 Cross-Site Request Forgery (CSRF) vulnerability in Wpjobportal WP JOB Portal
Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.
network
low complexity
wpjobportal CWE-352
8.8
2023-09-25 CVE-2023-4490 Unspecified vulnerability in Wpjobportal WP JOB Portal
The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
network
low complexity
wpjobportal
critical
9.8
2023-06-22 CVE-2023-28534 Cross-site Scripting vulnerability in Wpjobportal WP JOB Portal
Auth.
network
low complexity
wpjobportal CWE-79
5.4