Impact
A vulnerability exists in the JobBank plugin for WordPress that fails to properly neutralize user‑supplied input before echoing it back to the browser. When a specially crafted URL containing malicious JavaScript is accessed, the plugin can include that code in the page, allowing it to execute in the victim’s browser.
Affected Systems
All WordPress sites that install the e‑plugins JobBank plugin through version 1.2.2, including any build that uses 1.2.2 or earlier, are susceptible. The vulnerability is present in every installation of the plugin up to that version, regardless of site configuration.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity; the EPSS score is less than 1%, suggesting a low probability of exploitation. The vulnerability is reflected, so it requires that a victim click a crafted link or visit a malicious page; no persistent compromise is required. It is not listed in the CISA KEV catalog, but the high impact combined with the ease of delivery warrants immediate action.
OpenCVE Enrichment