Impact
Improper neutralization of input during web page generation in the Job Board Manager plugin allows a DOM‑based cross‑site scripting (XSS) flaw. A malicious actor can inject arbitrary JavaScript into pages rendered by the plugin, enabling client‑side code execution that may lead to session hijacking, credential theft, or defacement of content, depending on user engagement with the affected pages.
Affected Systems
The vulnerability is present in the WordPress Job Board Manager plugin developed by PickPlugins on all versions from the earliest release through and including version 2.1.61. Users running any of these versions on their WordPress sites are potentially affected.
Risk and Exploitability
The CVSS score of 6.5 signals moderate severity. The EPSS score is less than 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalogue. Attackers would need to target a user’s browser and convince them to visit a page that incorporates unsanitized input from the plugin, making the exploit client‑side and largely dependent on user interaction.
OpenCVE Enrichment
EUVD