Eyecix develops WordPress job-board and career-platform plugins that integrate into a broad range of hosted sites, creating a supply-chain exposure where a single flaw can affect numerous downstream instances. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through authorization and access-control weaknesses alongside cross-site scripting and input-handling flaws characteristic of WordPress plugin architecture. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eyecix over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11925CRITICAL The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying | Nov 28, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-8615CRITICAL The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() fun | Nov 6, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-47636CRITICAL Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9. | Oct 10, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-43931CRITICAL Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3. | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-8614HIGH The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all vers | Nov 6, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-11917HIGH The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'j | Apr 25, 2025 | 8.1 | 25 | NO | NO |
CVE-2024-43929CRITICAL Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4. | Nov 1, 2024 | 9.8 | 25 | NO | NO |
CVE-2021-4361HIGH The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in | Jun 7, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-1168MEDIUM There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1. | Apr 4, 2022 | 6.1 | 25 | NO | YES |
CVE-2024-43928HIGH Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4 | Nov 1, 2024 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eyecix.
Media articles that mention a CVE ID that affects a product developed by Eyecix — matched by CVE ID, not by vendor name.