Impact
An improper neutralization of input during web page generation flaw in the WordPress WPJobBoard plugin allows attackers to inject malicious scripts that are reflected back to users. This reflected XSS vulnerability can lead to malware execution, credential theft, or other phishing attacks when victims interact with the affected site. The weakness is identified as CWE‑79, a classic input validation flaw.
Affected Systems
The vulnerability affects any WordPress installation using the NotFound WPJobBoard plugin version 5.10.1 or earlier. Versions prior to 5.10.1 are also impacted, while 5.11.1 and newer are safe once the update is applied.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, but the EPSS score of less than 1% suggests that exploitation likelihood in the wild is currently very low. The vulnerability is not listed in CISA’s KEV catalog. Attack vectors are inferred to be remote, via crafted URLs or input fields exposed by the plugin, where an attacker can entice a victim to visit a malicious link to trigger the script. Once exploited, the resulting malicious payload executes in the context of the victim’s browser, compromising confidentiality, integrity, or availability of user data.
OpenCVE Enrichment
EUVD