Chameleoni Jobs
Chameleoni Jobs has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Chameleoni Jobs has a vendor fix available, so running the current release closes it.
All of these findings were reported by João Pedro Soares de Alcântara. Chameleoni Jobs is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-52459Chameleoni Jobs <= 2.5.4 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Chameleoni Jobs
Author
Chameleoni
This plugin adds Chameleoni Jobs feed to your WordPress site. Activate the plugin and configure your client login details in the plugin settings. Features include: Vacancy posting – post and manage your vacancies on your website. Candidate registration – job seekers register their details directly into your database. Job search – effective job search that delivers relevant results to the job seeker visiting your website. Candidate application – all applications are delivered directly to your database, ready for you to review. The ability to report on activity via your Chameleon-i dashboard. Styling The plugin can be styled to match your website by editing the css file at this location : /wp-content/plugins/chameleon-wp/css/job_style.css Viewing jobs To show the jobs on the frontend, create a page and place the shortcode [Jobs_disp_front] in it. Support For more support refer to: http://supportcentre.chameleoni.com/hc/en-us
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C