← WordPress Vulnerabilities
WordPress security by component

Jobs for WordPress

Jobs for WordPress is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: job-postings

CVE-2026-23806: Jobs for WordPress: A security weakness

Jobs for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.8.

PublishedMar 25, 2026
Known safe version2.8.1
Safe version
Mar 25, 2026 CVE-2026-23806
Jobs for WordPress: A security weakness
Jobs for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.8.
2.8.1
CVE7.5
NVDPending
Dec 24, 2025 CVE-2025-68597
Jobs for WordPress: Cross-site scripting
Jobs for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jun 20, 2025 CVE-2025-50050
Jobs for WordPress: Cross-site scripting
Jobs for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Mar 26, 2025 CVE-2025-1310
Jobs for: Filesystem traversal
Jobs for is affected by filesystem traversal. Exploitation requires at least subscriber-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVDPending
Apr 15, 2024 CVE-2024-32149
Jobs for WordPress: Cross-site scripting
Jobs for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
May 03, 2023 CVE-2023-26017
Job Postings: Cross-site scripting
Job Postings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Apr 23, 2023 CVE-2022-44743
Job Postings: Cross-site scripting
Job Postings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4