CVE-2026-39660
WP Job Manager
Minimum safe version
2.4.1
Update to 2.4.1 or later to address 15 fixable vulnerabilities
CVE-2026-25404
CVE-2024-34549
CVE-2023-52211
CVE-2023-52212
WP Job Manager < 1.23.8 - Reflected Cross-Site Scripting (XSS)
WP Job Manager < 1.26.2 - Unauthenticated Arbitrary File Upload
WP Job Manager < 1.29.3 - Unauthenticated Object Injection
WP Job Manager < 1.31.3 - Phar Deserialization
WP Job Manager < 1.23.8 - Multiple Cross-Site Scripting
WP Job Manager <= 1.26.1 - Arbitrary File Upload
WP Job Manager <= 1.29.2 - PHP Object Injection
WP Job Manager <= 1.31.2 - PHP Object Injection via PHAR Deserialization
WordPress WP Job Manager plugin <=1.29.2 - Unauthenticated Object Injection vulnerability
WordPress WP Job Manager plugin <= 1.31.2 - Phar Deserialization vulnerability
WordPress plugin "WP Job Manager" fails to restrict access permissions