Impact
The vulnerability is caused by improper neutralization of input during web page generation in the WordPress NooTheme Jobmonster theme, allowing reflected cross‑site scripting. This flaw, identified as CWE‑79, enables an attacker to inject arbitrary JavaScript that executes in the victim’s browser when a specially crafted URL is visited. Because the executed code runs within the victim’s session, the attacker could hijack sessions, deface content, or phish for credentials.
Affected Systems
The flaw exists in all releases of the NooTheme Jobmonster WordPress theme up to and including version 4.8.5. Any installation of the theme with a version 4.8.5 or earlier is affected; no specific edition or sub‑component is singled out.
Risk and Exploitability
The CVSS score of 7.1 places the vulnerability in the high severity range. The EPSS score of less than 1% indicates that widespread exploitation is unlikely at present, and the issue is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is without additional infrastructure; an attacker only needs to craft a malicious link and convince a victim to open it, which triggers the reflected script execution.
OpenCVE Enrichment