VK Google Job Posting Manager
VK Google Job Posting Manager has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for VK Google Job Posting Manager has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. VK Google Job Posting Manager is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-12836VK Google Job Posting Manager <= 1.2.23 - Authenticated (Author+) Stored Cross-Site Scripting via Job Description Field
Read the full analysisVulnerability Records
VK Google Job Posting Manager
Author
Vektor,Inc.
This is the job posting manager plugin designed to work with Google Job Posting. It mainly has tow functions. [ Generation of JSON-LD ] This plugin generates JSON-LD of your recruitment info to register Google Job Posting. While this plugin will generate JSON-LD, it doesn’t guarantee your recruitment info will display on Google Job Posting. Because the Google Job Posting algorithm is not public. [ Blocks ] You can also display your recruitment information by using Gutenberg custom block. We prepare some styles, you can choose what you prefer to. [ Custom Fields to enter recruitment info ] You can enter your recruitment info via each post’s custom fields, or you can use common fields in ‘Settings’ > ‘VK Job Posting Settings’. Once you fill out the common fields, you don’t need to fill duplicated info in each post such as company name, logo, and website. You can overwrite common fields value by fill out each post’s custom fields.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C