Impact
The vulnerability is an improper neutralization of user input during web page generation, allowing attackers to inject malicious JavaScript that executes in victims’ browsers. This type of flaw can enable session hijacking, defacement, and phishing attacks, as the injected script runs with the privilege of the user viewing the page.
Affected Systems
The flaw appears in the NooTheme Jobica Core WordPress plugin in all releases from the initial version up to and including version 1.4.1. Any WordPress site that has not installed a later update is exposed.
Risk and Exploitability
The base score of 7.1 indicates a high severity vulnerability, and while an exploit likelihood value is not provided, reflected XSS can be triggered simply by directing a user to a crafted URL or query string. Because malicious payloads are trivial to assemble and can be shared through emails or social media, the risk remains substantial until the plugin is patched or otherwise mitigated.
OpenCVE Enrichment