WP JobHunt <= 7.7 - Missing Authorization to Authenticated (Candidate+) Stored Cross-Site Scripting via 'status'
WP-jobhunt
Minimum safe version
7.7
Update to 7.7 or later to address 4 fixable vulnerabilities
WP JobHunt <= 7.7 - Authenticated (Candidate+) Insecure Direct Object Reference
WP JobHunt <= 7.6 - Authenticated (Candidate+) Stored Cross-Site Scripting via ‘cs_job_title’
WP JobHunt <= 7.6 Authenticated (Custom+) Authorization Bypass
WP JobHunt <= 7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Account Deletion
WordPress Better Customer List for WooCommerce Plugin <= 1.2.3 - Reflected Cross Site Scripting (XSS) vulnerability
WP JobHunt <= 7.1 - Unauthenticated Privilege Escalation via Email Update/Account Takeover
WP JobHunt <= 7.1 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover
WP JobHunt <= 7.1 - Authentication Bypass to Candidate
WP JobHunt <= 7.1 - Authentication Bypass
CVE-2018-19488
CVE-2018-19487