PressTigers Vulnerabilities and Affected Products
Vulnerabilities associated with Simple Job Board.
Products
Clear product- Simple Job Board7 vulnerabilities
- Simple Folio3 vulnerabilities
- Simple Testimonials Showcase3 vulnerabilities
- Simple Event Planner (WordPress plugin)2 vulnerabilities
- simple_job_board2 vulnerabilities
- ZIP Code Based Content Protection2 vulnerabilities
- Simple Owl Carousel1 vulnerability
- Universal Clocks1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-59579HIGH | WordPress Simple Job Board plugin <= 2.13.7 - Sensitive Data Exposure vulnerabilityInsertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows Retrieve Embedded Sensitive Data.This issue affects Simple Job Board: from n/a through <= 2.13.7. CWE-201Oct 22, 2025 | CVSS7.5v3.1 | EPSS0.365% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47188MEDIUM | WordPress Simple Job Board plugin <= 2.10.5 - Broken Access Control vulnerabilityMissing Authorization vulnerability in PressTigers Simple Job Board simple-job-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Job Board: from n/a through <= 2.10.5. CWE-862Jan 2, 2025 | CVSS5.3v3.1 | EPSS0.444% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7351HIGH | Simple Job Board <= 2.12.3 - Authenticated (Editor+) PHP Object InjectionThe Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbit… CWE-502Aug 24, 2024 | CVSS7.2v3.1 | EPSS0.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1813CRITICAL | Simple Job Board <= 2.11.0 - Unauthenticated PHP Object Injection via Job Application FieldsThe Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code when a submitte… CWE-502Apr 9, 2024 | CVSS9.8v3.1 | EPSS1.12% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0593MEDIUM | Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information DisclosureThe Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information. | CVSS5.3v3.1 | EPSS0.909% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-52122MEDIUM | WordPress Simple Job Board Plugin <= 2.10.6 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board.This issue affects Simple Job Board: from n/a through 2.10.6. CWE-352Jan 5, 2024 | CVSS4.3v3.1 | EPSS0.223% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-29440MEDIUM | WordPress Simple Job Board Plugin <= 2.10.3 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board plugin <= 2.10.3 versions. CWE-352Nov 10, 2023 | CVSS4.3v3.1 | EPSS0.315% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |