WordPress security by component
Jobs for WordPress
Plugin description
Jobs for WordPress is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
job-postingsLatest vulnerability
CVE-2026-23806: Jobs for WordPress: A security weakness
Jobs for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.8.
| Safe version |
|
||
|---|---|---|---|
| Mar 25, 2026 |
CVE-2026-23806
Jobs for WordPress: A security weakness
Jobs for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.8.
|
2.8.1 |
CVE7.5
NVDPending
|
| Dec 24, 2025 |
CVE-2025-68597
Jobs for WordPress: Cross-site scripting
Jobs for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 20, 2025 |
CVE-2025-50050
Jobs for WordPress: Cross-site scripting
Jobs for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Mar 26, 2025 |
CVE-2025-1310
Jobs for: Filesystem traversal
Jobs for is affected by filesystem traversal. Exploitation requires at least subscriber-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 15, 2024 |
CVE-2024-32149
Jobs for WordPress: Cross-site scripting
Jobs for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| May 03, 2023 |
CVE-2023-26017
Job Postings: Cross-site scripting
Job Postings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Apr 23, 2023 |
CVE-2022-44743
Job Postings: Cross-site scripting
Job Postings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|