Impact
The plugin fails to neutralize user supplied data before rendering it in a browser page, so attackers can inject script code that will run when a user visits the page. A malicious actor could steal session cookies, phishing credentials, or deface the site, compromising confidentiality and integrity. The flaw is a classic reflection of user input, classified as a cross site scripting weakness.
Affected Systems
All installations of the WordPress Addon Jobsearch Chat plugin developed by Eyecix with version 3.0 or earlier are affected. Versions newer than 3.0 have not been confirmed to contain the flaw.
Risk and Exploitability
The CVSS score of 7.1 reflects moderate to high severity. Because the flaw is a reflected XSS, exploitation requires only that a victim visit a specially crafted URL or submit malicious input, a simple attack vector that does not need privileged access. The EPSS score is unavailable and the vulnerability is not listed in KEV, but the ease of exploitation makes it realistic for exposed sites that allow untrusted input.
OpenCVE Enrichment