
Custom Field For WP Job Manager Security & Risk Analysis
wordpress.org/plugins/custom-field-for-wp-job-managerThe ultimate field editor for WP Job Manager. Easily add, edit, and manage custom job and company fields without any coding.
Is Custom Field For WP Job Manager Safe to Use in 2026?
Generally Safe
Score 97/100Custom Field For WP Job Manager has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of "custom-field-for-wp-job-manager" v1.5 reveals a generally positive security posture, with several key strengths. Notably, the plugin demonstrates excellent practices in handling SQL queries, exclusively using prepared statements, and all output is properly escaped, indicating a strong defense against common injection and XSS vulnerabilities. The absence of file operations and external HTTP requests further reduces the attack surface. However, a significant concern arises from the REST API, where one of the four routes lacks a permission callback, creating a potential entry point for unauthorized actions. While taint analysis found no issues, this unprotected REST API endpoint warrants immediate attention.
The vulnerability history shows a concerning pattern of past medium-severity issues, including CSRF, authorization bypass, and XSS. The fact that there are 5 known CVEs, even though none are currently unpatched, suggests that the plugin has had recurring security flaws. The recurrence of these vulnerability types indicates potential weaknesses in input validation and authorization logic that may not have been fully addressed in past fixes or could re-emerge. The most recent vulnerability was in March 2025, which implies that even the latest version (v1.5) may have had issues discovered very recently, or the data is referencing a future date.
In conclusion, while the plugin exhibits robust coding practices regarding SQL and output sanitization, the unprotected REST API endpoint represents a critical oversight. The historical trend of medium-severity vulnerabilities, despite the current lack of unpatched issues, suggests a need for continued vigilance and thorough auditing to ensure these past weaknesses are truly remediated. Addressing the unprotected REST API should be the highest priority.
Key Concerns
- Unprotected REST API route
- History of 5 medium CVEs
Custom Field For WP Job Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Custom Field For WP Job Manager <= 1.4 - Cross-Site Request Forgery
Custom Field For WP Job Manager <= 1.3 - Reflected Cross-Site Scripting
Custom Field For WP Job Manager <= 1.2 - Insecure Direct Object Reference to Sensitive Information Exposure via Shortcode
Custom Field For WP Job Manager <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Custom Field For WP Job Manager <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Custom Field For WP Job Manager Code Analysis
Output Escaping
Custom Field For WP Job Manager Attack Surface
REST API Routes 4
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
Custom Field For WP Job Manager Maintenance & Trust
Maintenance Signals
Community Trust
Custom Field For WP Job Manager Alternatives
Job Manager & Career – Manage job board listings, and recruitments
job-manager-career
An ideal WordPress Job Manager plugin for recruiters to manage job board listings, career pages, and recruitments.
Custom Job Fields for WP Job Manager
custom-job-fields-for-wp-job-manager
Custom Job Fields for WP Job Manager is flexible and easy to add your custom fields for WP Job Manager.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Checkout Field Editor (Checkout Manager) for WooCommerce
woo-checkout-field-editor-pro
Checkout Field Editor (Checkout Manager) for WooCommerce – The best WooCommerce checkout manager plugin to manage WooCommerce checkout fields.
Custom Field For WP Job Manager Developer Profile
26 plugins · 12K total installs
How We Detect Custom Field For WP Job Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-field-for-wp-job-manager/build/admin/admin.css/wp-content/plugins/custom-field-for-wp-job-manager/build/admin/admin.jswp-content/plugins/custom-field-for-wp-job-manager/build/admin/admin.jsHTML / DOM Fingerprints
headingmcCFWJM-admin-rootcfwjm_wp_ajax/wp-json/cfwjm/v1/get_fields/wp-json/cfwjm/v1/add_field/wp-json/cfwjm/v1/update_field/wp-json/cfwjm/v1/delete_field[cm_fieldshow key='_field_cfwjm