Vulnerabilities
Vulnerable Software
Wpjobboard:  >> Wpjobboard  Security Vulnerabilities
The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.
CVSS Score
6.1
EPSS Score
0.001
Published
2020-02-25
The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-alerts module, with a request to wp-admin/admin.php.
CVSS Score
7.2
EPSS Score
0.005
Published
2018-01-14
Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query` and `id` parameters of the `wpjb-email`, `wpjb-job`, `wpjb-application`, and `wpjb-membership` modules. Remote attackers are able to inject malicious script code to hijack admin session credentials via the backend, or to manipulate the backend on client-side performed requests. The attack vector is non-persistent and the request method to inject is GET. The attacker does not need a privileged user account to perform a successful exploitation.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-10-16


Contact Us

Shodan ® - All rights reserved