Eyecix

Jobsearch Wp Job Board

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 25.04.2025 11:12:52
  • Zuletzt bearbeitet 17.06.2025 19:15:25

The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google...

  • EPSS 0.15%
  • Veröffentlicht 28.11.2024 07:15:05
  • Zuletzt bearbeitet 28.11.2024 07:15:05

The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_acco...

  • EPSS 12.82%
  • Veröffentlicht 06.11.2024 09:15:04
  • Zuletzt bearbeitet 08.11.2024 20:23:41

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authentic...

  • EPSS 13.36%
  • Veröffentlicht 06.11.2024 09:15:04
  • Zuletzt bearbeitet 08.11.2024 20:24:28

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possi...

  • EPSS 0.32%
  • Veröffentlicht 01.11.2024 15:15:49
  • Zuletzt bearbeitet 12.11.2024 20:49:01

Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.

  • EPSS 0.38%
  • Veröffentlicht 01.11.2024 15:15:49
  • Zuletzt bearbeitet 12.11.2024 20:49:57

Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.

  • EPSS 0.85%
  • Veröffentlicht 10.10.2024 18:15:07
  • Zuletzt bearbeitet 12.11.2024 20:52:49

Deserialization of Untrusted Data vulnerability in Eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.9.

  • EPSS 1.19%
  • Veröffentlicht 29.08.2024 15:15:29
  • Zuletzt bearbeitet 13.09.2024 21:22:51

Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.

  • EPSS 0.35%
  • Veröffentlicht 19.08.2024 18:15:10
  • Zuletzt bearbeitet 19.08.2024 18:36:07

Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 27.02.2024 09:15:37
  • Zuletzt bearbeitet 01.05.2025 15:28:07

The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.