{"error":0,"message":null,"data":{"name":"WP Job Manager","plugin":"wp-job-manager","link":"https:\/\/wordpress.org\/plugins\/wp-job-manager\/","latest":"1788436740","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"e4a65311a73d489981d8c46609249cb4af6c457a87044366b675ef22d1c4663f","name":"WP Job Manager [wp-job-manager] < 1.26.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.26.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"JVNDB-2017-000139","name":"WordPress plugin \"WP Job Manager\" fails to restrict access permissions","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2017-000139","description":"The WordPress plugin \"WP Job Manager\" provided by Automattic Inc. fails to restrict access permissions.  Katsunori Kumagai of Kumasan, LLC. reported this issue to IPA under Information Security Early Warning Partnership.","date":"2017-06-15"}],"impact":[]},{"uuid":"7690abafa4f4be138694b99eb5ea33233f2f3e8ced7f1581bb1cda3f2cec0e94","name":"WP Job Manager [wp-job-manager] < 1.31.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.31.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"179aa3f0d1761d76da265cd640c7f78cc130d5da","name":"WordPress WP Job Manager plugin <= 1.31.2 - Phar Deserialization vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-job-manager\/vulnerability\/wordpress-wp-job-manager-plugin-1-31-2-phar-deserialization-vulnerability","description":"Phar Deserialization vulnerability found by Ripstech in WordPress WP Job Manager plugin (versions <= 1.31.2).","date":"2019-01-07"}],"impact":[]},{"uuid":"de342c07dcd3bd8b77f34d10d59f24531ad9969e150c12be830c37a8807b2fe6","name":"WP Job Manager [wp-job-manager] < 1.29.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.29.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fff1f045ad14fe0433faadbfd27f77a12f97f841","name":"WordPress WP Job Manager plugin <=1.29.2 - Unauthenticated Object Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-job-manager\/vulnerability\/wordpress-wp-job-manager-plugin-1-29-2-unauthenticated-object-injection-vulnerability","description":"Unauthenticated Object Injection vulnerability found in WordPress WP Job Manager plugin (versions <=1.29.2).","date":"2018-03-15"}],"impact":[]},{"uuid":"aa85dcee79b5fe2aec48cc1eebef3fe3ea46a50372765571bbb243d142a52442","name":"WP Job Manager [wp-job-manager] < 1.31.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.31.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ca91454695b523f764f5314f147a15b42d2399d7","name":"WP Job Manager <= 1.31.2 - PHP Object Injection via PHAR Deserialization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-job-manager\/wp-job-manager-1312-php-object-injection-via-phar-deserialization","description":"TheWP Job Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.31.2 via deserialization of user-controlled input allowing a phar wrapper. This allows attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2019-01-07"}],"impact":[]},{"uuid":"a0616fd231ca478a5b46493b6e2e3b808230d56dc806abc66dd8982a6abca242","name":"WP Job Manager [wp-job-manager] < 1.29.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.29.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"40c4089404e2c329d1b2bb78f898784463dd395e","name":"WP Job Manager <= 1.29.2 - PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-job-manager\/wp-job-manager-1292-php-object-injection","description":"The WP Job Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.29.2 via deserialization of untrusted input in the get_job_listings function. This allows unauthorized attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to implement their own payload and\/or unserialize malicious input.","date":"2018-03-02"}],"impact":[]},{"uuid":"a02e4bbdecd5e2b881e7943f6b91a4ef906fb5f3b4ac1eb6ec8052f53a88e312","name":"WP Job Manager [wp-job-manager] < 1.26.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.26.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b4d8c2f9d80c4647e93f4d7ff7d9b92a20a8a4cd","name":"WP Job Manager <= 1.26.1 - Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-job-manager\/wp-job-manager-1261-arbitrary-file-upload","description":"The WP Job Manager plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the via the ~\/class-wp-job-manager-ajax.php file in versions up to, and including, 1.26.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.","date":"2016-07-11"}],"impact":[]},{"uuid":"1c8209fc54ce069fdd4520e0c4f9b443c56f2c8834acd1904b7d50853357f479","name":"WP Job Manager [wp-job-manager] < 1.23.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.23.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"20302d82235ae07e8ea1fcdf9d759c339efb1aef","name":"WP Job Manager < 1.23.8 - Multiple Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-job-manager\/wp-job-manager-1238-multiple-cross-site-scripting","description":"The WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018create_account_email' and 'create_account_username\u2019 parameters in versions up to, and including, 1.23.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2015-08-20"}],"impact":[]},{"uuid":"f8eb74258b1b0816d92fdc15633dbac1225f29530c1d617d0204cf9a978f0998","name":"WP Job Manager [wp-job-manager] < 1.31.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.31.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"382e1efb-ce01-46bd-b22f-3c681ea47ea0","name":"WP Job Manager &lt; 1.31.3 - Phar Deserialization","link":"https:\/\/wpscan.com\/vulnerability\/382e1efb-ce01-46bd-b22f-3c681ea47ea0","description":"The WP Job Manager WordPress plugin was affected by a Phar Deserialization security vulnerability.","date":null}],"impact":[]},{"uuid":"ed37cfd3a445a7ebd6860e9a0aa5eaf43c62da706d834f8f98932c2f987ea851","name":"WP Job Manager [wp-job-manager] < 1.29.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.29.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3c520e91-c686-4cc3-93c3-823f6a60969c","name":"WP Job Manager &lt; 1.29.3 - Unauthenticated Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/3c520e91-c686-4cc3-93c3-823f6a60969c","description":"Preauth PHP Object injection -  unauthenticated attacker could supply his own payload and system to perform unserialize over its data.","date":null}],"impact":[]},{"uuid":"f5d4019da1459ad05f09715319352a17812440857a64bf83f62d43171c423eee","name":"WP Job Manager [wp-job-manager] < 1.26.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.26.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3d653568-3159-46eb-9dc7-d51af09e8f1d","name":"WP Job Manager &lt; 1.26.2 - Unauthenticated Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/3d653568-3159-46eb-9dc7-d51af09e8f1d","description":"The WP Job Manager WordPress plugin was affected by an Unauthenticated Arbitrary File Upload security vulnerability.","date":null}],"impact":[]},{"uuid":"8d96a3c6bbc7ee6b16fdb066cd434639e383d0a4d80bd25dce17a53e37289266","name":"WP Job Manager [wp-job-manager] < 1.23.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.23.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b581499c-7ccf-48fe-88f1-c27a04ad5aaf","name":"WP Job Manager &lt; 1.23.8 - Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/b581499c-7ccf-48fe-88f1-c27a04ad5aaf","description":"The WP Job Manager WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"bb3ce65d313eac91e25f397d2b776de3f200c476aa35de7eb903239d51c2f4ec","name":"WP Job Manager [wp-job-manager] < 2.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-52212","name":"CVE-2023-52212","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-52212","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issue affects WP Job Manager: from n\/a through 2.0.0.","date":"2026-01-05"},{"id":"59cdce95a098a8abc546fb18b0dbd4fe9be57347","name":"WordPress  WP Job Manager Plugin  <= 2.0.0 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-job-manager\/vulnerability\/wordpress-wp-job-manager-plugin-2-0-0-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress WP Job Manager plugin to the latest available version (at least 2.1.0).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WP Job Manager Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 2.1.0.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-05"},{"id":"a40afb1a2a0c8fbd240a894ac95486a1dea43ea3","name":"WP Job Manager <= 2.0.0 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-job-manager\/wp-job-manager-200-cross-site-request-forgery","description":"The WP Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation on the settings_save() function. This makes it possible for unauthenticated attackers to save settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-01-05"},{"id":"1306bbec-e7e0-4c8e-871d-017bb7b6056f","name":"WP Job Manager &lt; 2.1.0 - Cross-Site Request Forgery","link":"https:\/\/wpscan.com\/vulnerability\/1306bbec-e7e0-4c8e-871d-017bb7b6056f","description":"The WP Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation on the settings_save() function. This makes it possible for unauthenticated attackers to save settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":null},{"id":"EUVD-2023-56885","name":"EUVD-2023-56885","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2023-56885","description":"Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issue affects WP Job Manager: from n\/a through 2.0.0.","date":"2026-01-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6c7bc8d36b90b9af54545e3c1d69b3f3b5362b3d3edbb12758b7a0f8b307328e","name":"WP Job Manager [wp-job-manager] < 2.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-52211","name":"CVE-2023-52211","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-52211","description":"[en] Missing Authorization vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n\/a through 2.0.0.","date":"2024-04-12"},{"id":"1562b509b03f5ed4fd24d28cb0411f18c8738d7b","name":"WordPress  WP Job Manager Plugin  <= 2.0.0 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-job-manager\/vulnerability\/wordpress-wp-job-manager-plugin-2-0-0-unauthenticated-broken-access-control-vulnerability","description":"Update the WordPress WP Job Manager plugin to the latest available version (at least 2.1.0).\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress WP Job Manager Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 2.1.0.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-05"},{"id":"789dbde14d178acd635c97b13cf0927988d4cefb","name":"WP Job Manager <= 2.0.0 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-job-manager\/wp-job-manager-200-missing-authorization","description":"The WP Job Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rest route associated with the update_job_status function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to update job statuses.","date":"2024-01-05"},{"id":"db4124d8-88b3-42c7-a641-8fcfc96b9e60","name":"WP Job Manager &lt; 2.1.0 - Unauthenticated Job Status Update","link":"https:\/\/wpscan.com\/vulnerability\/db4124d8-88b3-42c7-a641-8fcfc96b9e60","description":"The plugin does not properly authorize the use of some endpoints, allowing an unauthenticated attacker to update job statuses.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2ee24bcd6119aaa847241273a47fee6c7c6bbb0d0c7a0a5d80f1f16137bd766e","name":"WP Job Manager [wp-job-manager] < 2.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-34549","name":"CVE-2024-34549","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-34549","description":"[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n\/a through 2.2.2.","date":"2024-05-09"},{"id":"ab0fc093a1715bd112d6df1406ef97507499bf6b","name":"WordPress WP Job Manager Plugin <= 2.2.2 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-job-manager\/vulnerability\/wordpress-wp-job-manager-plugin-2-2-2-sensitive-data-exposure-vulnerability","description":"<p>WordPress WP Job Manager Plugin <= 2.2.2 is vulnerable to Sensitive Data Exposure<\/p><p>Software: WP Job Manager<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-job-manager\/#developers<\/p><p>Affected Version <= 2.2.2<\/p><p>Fixed in version 2.3.0 <\/p>","date":"2024-05-07"},{"id":"a83251888b5c6deef49300173bab4ad962864334","name":"WP Job Manager <= 2.2.2 - Unauthenticated Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-job-manager\/wp-job-manager-222-unauthenticated-information-exposure","description":"The WP Job Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2024-05-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d38ad591b4ffc848da7650cd2b65fbbd9104c669181f6e3adf4d4968ea16dfc1","name":"WP Job Manager [wp-job-manager] < 2.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-25404","name":"CVE-2026-25404","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-25404","description":"[en] Missing Authorization vulnerability in Automattic WP Job Manager wp-job-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Manager: from n\/a through <= 2.4.0.","date":"2026-02-19"},{"id":"8ac75d0b3012216f4214abb08b6e583f1b9d5d26","name":"WP Job Manager <= 2.4.0 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-job-manager\/wp-job-manager-240-missing-authorization","description":"The WP Job Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-01-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e2b504fd666ed25925c93e4ab93ac0838133e2231d11ef7e0a02fc910c11adf9","name":"WP Job Manager [wp-job-manager] <= 2.4.1 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.1","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-39660","name":"CVE-2026-39660","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-39660","description":"","date":"2026-04-08"},{"id":"EUVD-2026-20330","name":"EUVD-2026-20330","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-20330","description":"Missing Authorization vulnerability in Automattic WP Job Manager wp-job-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Manager: from n\/a through <= 2.4.1.","date":"2026-04-08"},{"id":"a9515df85dfef5b0c5d983244ebfadfc8be70d5f","name":"Job Manager <= 2.4.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-job-manager\/job-manager-241-missing-authorization","description":"The Job Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.4.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-02-17"}],"impact":[]}]},"updated":"1789280367"}