Impact
The Job Postings plugin for WordPress is vulnerable to Stored Cross‑Site Scripting because the 'position_button' parameter is not properly sanitized or escaped. This flaw allows an authenticated user with contributor-level access or higher to inject malicious JavaScript into job listings that will run whenever a victim visits the page. The vulnerability is a classic input validation error, classified as CWE‑79.
Affected Systems
Affected systems are WordPress sites that have the Job Postings plugin installed at version earlier revision. Users with contributor or higher privileges can exploit the flaw; therefore any site allowing such roles to edit job postings is at risk. No other plugin versions beyond 2.8.1 are mentioned as vulnerable in the current data.
Risk and Exploitability
The a moderate severity; the EPSS score of less than 1 % suggests an unlikely but possible exploitation. The risk is amplified by the requirement for authenticated access—the attacker must possess a contributor or higher account. Since the vulnerability is not listed in the CISA KEV catalog, there is no for user‑targeted XSS remains significant. The likely attack vector is an authenticated user creating or editing a job listing, which could then be exploited by other site visitors.
OpenCVE Enrichment