Blueglass maintains a WordPress plugin product with a modestly represented vulnerability footprint concentrated around input-handling weaknesses in web-page generation contexts, particularly cross-site scripting. The plugin's exposure profile reflects the common challenges of web-application form handling and output encoding in third-party WordPress extensions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blueglass over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44743MEDIUM Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.11.2 versions. | Apr 23, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-10104MEDIUM The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as contributor to perform Stored Cross | Nov 15, 2024 | 5.9 | 18 | NO | NO |
CVE-2024-32149MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Jobs for WordPress allows Reflected XSS.This issue affects Jobs for | Apr 15, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-26017MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.10.2 versions. | May 3, 2023 | 4.8 | 18 | NO | NO |
CVE-2024-10105MEDIUM The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cros | Mar 25, 2025 | 5.9 | 17 | NO | NO |
CVE-2024-2833MEDIUM The Jobs for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘job-search’ parameter in all versions up to, and including, 2.7.5 due to insuff | Apr 18, 2024 | 6.1 | 17 | NO | NO |
CVE-2024-0820MEDIUM The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scri | Mar 18, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blueglass.
Media articles that mention a CVE ID that affects a product developed by Blueglass — matched by CVE ID, not by vendor name.