Click & Pledge WPJobBoard
Click & Pledge WPJobBoard has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is SQL Injection, behind 1 of the records (100%).
The one issue recorded for Click & Pledge WPJobBoard has a vendor fix available, so running the current release closes it.
All of these findings were reported by timomangcut. Click & Pledge WPJobBoard is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
WordPress-WPJobBoard <= 25.07010000-WP6.8.1-JB5.11.5 - Unauthenticated SQL Injection
Read the full analysisVulnerability Records
Click & Pledge WPJobBoard
Author
ClickandPledge
The Click & Pledge WBJobBoard plugin is a 3rd party add-on to the WPJobBoard plugin. The plugin allows the Site Owner to embed a payment form to process payments via Visa, American Express, Discover, and Mastercard through their Click & Pledge Merchant Account. Payment form data posts via an encrypted connection from your SSL-secured site to <a href=”https://paas.cloud.clickandpledge.com/PaymentService.svc?wsdl target=”_blank”>https://paas.cloud.clickandpledge.com/PaymentService.svc?wsdl, Click & Pledge’s Payment Application Interface (PAI) for the Trio payment and administrative engine. Available posting methods are * Operation * OperationBase64Encode * Echo Security Details are available at: https://clickandpledge.com/about/our-security/ Review the Click & Pledge Privacy Statement at: https://clickandpledge.com/privacy/ About Click & Pledge Click & Pledge is a Level 1 PCI DSS-certified payment services provider offering products to over 20,000 clients worldwide. Required Settings * Account Number * Account GUID * Account Type (USD, EUR, CAD, GBP, or HKD) To locate Account Number and API Account GUID: Login into Click & Pledge Connect, the online interface for a Click & Pledge account Navigate to Settings – API Information. Minimum Requirements WordPress 3.3 (it will work with WordPress 3.0 but 3.3 version is recommended)PHP 5.2.4 or greater PHP 5.2.0 MySQL 5.0+ Hosting Site secured via SSL Click & Pledge Account
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C