That”s what I already told in this post on February 20th
I am not sure if the 10month timeframe is the only problem at the moment. Currently Wordfence, iThemes Security Pro and Plesks’ WordPress-Toolkit announce a XSS-Vulnerability.
see this topic in its WP Support thread.
see the Details at Wordfence
WordPress-Toolkit of Plesk reports this, too.
I remember pressing the “Support”-Link here:
https://de.ww.wp.xz.cn/plugins/job-postings/
Sorry, that there was no link to the affected plugin.