Eklenti güvenlik geçmişi
Job Postings güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Job Postings eklentisi için 2 açık kaydı bulunuyor; en yenisi 15 Eylül 2026 tarihli. Bunların 0 tanesi kritik veya yüksek önemde, 0 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 2.8.2.
- Toplam kayıt
- 2
- Kritik veya yüksek
- 0
- Oturumsuz istismar
- 0
- Son kayıt
- 15 Eylül 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.8.1 ve öncesi
The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.7.11 öncesi
The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.