Impact
An attacker can inject malicious JavaScript into the WordPress JobSearch plugin user‑provided content during page rendering. When a job posting or similar input is saved, the dangerous payload is stored and later displayed to all visitors, enabling data theft or session hijacking. The primary impact is that a compromised page can execute arbitrary scripts in the browsers of site visitors.
Affected Systems
The vulnerability exists in the eyecix JobSearch WordPress plugin through version 3.2.9. Any WordPress site that has installed this plugin at 3.2.9 or an earlier release is susceptible.
Risk and Exploitability
With a CVSS score of 7.1 and an EPSS score below 1%, the risk level is moderate but exploitation is still possible. The likely attack vector is inferred from the description: an attacker would need to add or edit content that the plugin stores, which typically requires administrative or content‑author privileges. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment