Impact
The flaw is an improper neutralization of input during page rendering, classified as a Reflected Cross‑Site Scripting (CWE‑79). An attacker can embed malicious JavaScript into a URL that, when accessed by a victim, is reflected back into the page without sanitization. This ability could lead to cookie theft, session hijacking, defacement, or malware deployment through the victim’s browser.
Affected Systems
Astoundify’s Jobify WordPress theme, version 4.3.0 and earlier, is vulnerable. Any site using these legacy releases is at risk until the theme is updated to a patched version.
Risk and Exploitability
The CVSS base score of 7.1 signals high severity, while an EPSS score below 1% indicates a low overall likelihood of exploitation at present. The issue is not listed in the CISA KEV catalog. Exploitation requires remote web access; a specially crafted link that injects JavaScript into a job page must be visited by a target user. The vulnerability has no local privilege or code‑execution component.
OpenCVE Enrichment