CVE-2024-11917
- EPSS 0.36%
- Veröffentlicht 25.04.2025 11:12:52
- Zuletzt bearbeitet 17.06.2025 19:15:25
The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google...
CVE-2024-11925
- EPSS 0.15%
- Veröffentlicht 28.11.2024 07:15:05
- Zuletzt bearbeitet 28.11.2024 07:15:05
The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_acco...
CVE-2024-8614
- EPSS 12.82%
- Veröffentlicht 06.11.2024 09:15:04
- Zuletzt bearbeitet 08.11.2024 20:23:41
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authentic...
CVE-2024-8615
- EPSS 13.36%
- Veröffentlicht 06.11.2024 09:15:04
- Zuletzt bearbeitet 08.11.2024 20:24:28
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possi...
CVE-2024-43928
- EPSS 0.32%
- Veröffentlicht 01.11.2024 15:15:49
- Zuletzt bearbeitet 12.11.2024 20:49:01
Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.
CVE-2024-43929
- EPSS 0.38%
- Veröffentlicht 01.11.2024 15:15:49
- Zuletzt bearbeitet 12.11.2024 20:49:57
Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.
CVE-2024-47636
- EPSS 0.85%
- Veröffentlicht 10.10.2024 18:15:07
- Zuletzt bearbeitet 12.11.2024 20:52:49
Deserialization of Untrusted Data vulnerability in Eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.9.
CVE-2024-43931
- EPSS 1.19%
- Veröffentlicht 29.08.2024 15:15:29
- Zuletzt bearbeitet 13.09.2024 21:22:51
Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.
CVE-2024-43245
- EPSS 0.35%
- Veröffentlicht 19.08.2024 18:15:10
- Zuletzt bearbeitet 19.08.2024 18:36:07
Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.
CVE-2023-6584
- EPSS 0.29%
- Veröffentlicht 27.02.2024 09:15:37
- Zuletzt bearbeitet 01.05.2025 15:28:07
The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.