Impact
An improper neutralization of input during web page generation allows attackers to inject malicious scripts that execute in the browsers of users who view job postings. The stored XSS can be leveraged for session hijacking, defacement, or phishing attacks against visitors (inferred from typical XSS impacts). The weakness is a classic input validation failure classified as CWE‑79.
Affected Systems
The vulnerability exists in the Vektor, Inc. VK Google Job Posting Manager WordPress plugin for all releases up to and including version 1.2.22. Administrators using any of those versions on a WordPress site are potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. An EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the job posting creation or editing interface, where an attacker can inject a script payload (inferred). An attacker must first possess the ability to create or edit a job posting; the payload is then stored and executed when any site visitor views the malicious posting (inferred). While not widespread, the risk remains significant because the attack surface is persistent and can affect any visitor to the site.
OpenCVE Enrichment