Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation in the Jobs for WordPress plugin. Malicious content that an attacker can embed into a job posting can be rendered as part of the page viewed by site visitors, allowing the injected script to run in their browsers.
Affected Systems
All installations of BlueGlass Interactive AG's Jobs for WordPress plugin through version 2.8.1 on WordPress websites are affected. The flaw is present in every release from the earliest version up to and including 2.8.1.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. An EPSS score of less than 1% shows a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The stored XSS can be triggered by submitting data to a field that is later displayed to any visitor of the site.
OpenCVE Enrichment