CVE-2025-60162: WordPress Job Board Manager Plugin <= 2.1.61 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager allows DOM-Based XSS. This issue affects Job Board Manager: from n/a through 2.1.61.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows DOM-Based XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60162?
CVE-2025-60162 is classified as a High severity vulnerability due to its potential for exploitation via Cross-Site Scripting (XSS).
How do I fix CVE-2025-60162?
To mitigate CVE-2025-60162, upgrade your PickPlugins Job Board Manager or WordPress Job Board Manager Plugin to a version later than 2.1.61.
What type of vulnerability is CVE-2025-60162?
CVE-2025-60162 is an Improper Neutralization of Input During Web Page Generation vulnerability leading to DOM-Based Cross-Site Scripting.
Which versions are affected by CVE-2025-60162?
CVE-2025-60162 affects PickPlugins Job Board Manager versions up to and including 2.1.61.
Can CVE-2025-60162 be exploited remotely?
Yes, CVE-2025-60162 can be exploited remotely by an attacker to execute malicious scripts in the context of the user's browser.