
Click & Pledge WPJobBoard Security & Risk Analysis
wordpress.org/plugins/click-pledge-wpjobboardClick & Pledge payment gateway integration for WPJobBoard with Salesforce support.
Is Click & Pledge WPJobBoard Safe to Use in 2026?
Generally Safe
Score 98/100Click & Pledge WPJobBoard has a strong security track record. Known vulnerabilities have been patched promptly.
The "click-pledge-wpjobboard" plugin exhibits a mixed security posture. While it shows strengths in its use of prepared statements for SQL queries and proper output escaping, significant concerns are raised by the lack of authentication and capability checks on all identified AJAX handlers. The presence of 24 unprotected AJAX entry points is a substantial risk, as it means any unauthenticated user could potentially trigger these functions, leading to unintended actions or information disclosure.
Taint analysis reveals 7 flows with unsanitized paths, 4 of which are of high severity. This, coupled with the complete absence of nonce checks on AJAX actions, strongly suggests a vulnerability to cross-site request forgery (CSRF) or similar attacks that could exploit these unprotected entry points. The plugin's history of a high severity SQL injection vulnerability, although currently patched, also indicates a past weakness in how user-supplied data was handled, reinforcing the concern about unsanitized input in the current version.
In conclusion, the plugin has adopted some good security practices like prepared statements and output escaping. However, the massive attack surface exposed through unprotected AJAX handlers and the critical findings in taint analysis present a clear and present danger. The historical SQL injection vulnerability further highlights the need for rigorous input validation and authorization checks on all entry points. Until these critical authorization and sanitization issues are addressed, the plugin remains a significant security risk.
Key Concerns
- All 24 AJAX handlers are unprotected
- 4 High severity taint flows with unsanitized paths
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
- 7 flows with unsanitized paths
- History of a high severity SQL Injection CVE
Click & Pledge WPJobBoard Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WordPress-WPJobBoard <= 25.07010000-WP6.8.1-JB5.11.5 - Unauthenticated SQL Injection
Click & Pledge WPJobBoard Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Click & Pledge WPJobBoard Attack Surface
AJAX Handlers 24
WordPress Hooks 4
Maintenance & Trust
Click & Pledge WPJobBoard Maintenance & Trust
Maintenance Signals
Community Trust
Click & Pledge WPJobBoard Alternatives
Click & Pledge for Gravity Forms
gravity-forms-click-pledge
Add a credit card payment gateway for Click & Pledge to the Gravity Forms plugin
Click & Pledge – Paid Memberships Pro
click-pledge-paid-memberships-pro
Click & Pledge payment gateway integration for Paid Memberships Pro with Salesforce support.
Bykea.Cash – Online Payments
bykea-cash-online-payments
The Bykea Cash plugin allows you to collect payments on your WordPress WooCommerce website instantly using Credit/Debit Cards (VISA, MasterCard, PayPa …
Paystation Payment Gateway for woocommerce
paystation-woocommerce-payment-gateway
Take credit card payments on your store via Paystation.
Pay Advantage
pay-advantage
Instantly accept Visa, Mastercard and American Express from your site with fast settlement to any Australian bank account.
Click & Pledge WPJobBoard Developer Profile
5 plugins · 190 total installs
How We Detect Click & Pledge WPJobBoard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/click-pledge-wpjobboard/clickandpledge-admin.js/wp-content/plugins/click-pledge-wpjobboard/clickandpledge.css/wp-content/plugins/click-pledge-wpjobboard/clickandpledge-admin.jsclick-pledge-wpjobboard/clickandpledge.css?ver=click-pledge-wpjobboard/clickandpledge-admin.js?ver=HTML / DOM Fingerprints
cnpwpjblogincnpwpjblogintitlecnpwpjbsettings<!-- Click & Pledge [you are logged in as: translators: %s is the username of the logged-in Click & Pledge accounttranslators: %s is the username of the logged-in Click & Pledge accountClick & Pledge+6 morewpjobboard_clickandpledge_registerwpjobboard_clickandpledge_Settingswpjobboard_clickandpledge_AccountIDwpjobboard_clickandpledge_OrderModewpjobboard_clickandpledge_ConnectCampaignAliaswpjobboard_clickandpledge_apiSettingsPayment_ClickandPledgeWpjb_Form_Abstract_Payment