What this page helps you verify fast
This hub clusters every indexed record for Careerfy - Job Board WordPress Theme so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress theme Careerfy - Job Board WordPress Theme (`careerfy`), including severity, CVE references, affected versions, and patch status.
Start with the highest-signal CVE records for this WordPress theme before scanning the full vulnerability feed.
This hub clusters every indexed record for Careerfy - Job Board WordPress Theme so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Careerfy theme for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 7.0. This is due to missing nonce validation and capabil...
The Careerfy for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for una...
The Careerfy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This make...
Sorted by latest disclosure date so newly published issues surface first.
The Careerfy theme for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 7.0. This is due to missing nonce validation and capability checks on several functions. This makes it possible for authenticated attackers, with...
The Careerfy for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...
The Careerfy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
The Careerfy theme for WordPress is vulnerable to Multiple Cross-Site Scripting in versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in...
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficient input sanitization and...
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insu...
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated...
The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', and 'Full Address' fields in versions up to,...
The Careerfy theme plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.