Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can inject malicious JavaScript into the WordPress JobSearch plugin user‑provided content during page rendering. When a job posting or similar input is saved, the dangerous payload is stored and later displayed to all visitors, enabling data theft or session hijacking. The primary impact is that a compromised page can execute arbitrary scripts in the browsers of site visitors.

Affected Systems

The vulnerability exists in the eyecix JobSearch WordPress plugin through version 3.2.9. Any WordPress site that has installed this plugin at 3.2.9 or an earlier release is susceptible.

Risk and Exploitability

With a CVSS score of 7.1 and an EPSS score below 1%, the risk level is moderate but exploitation is still possible. The likely attack vector is inferred from the description: an attacker would need to add or edit content that the plugin stores, which typically requires administrative or content‑author privileges. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 31, 2026 at 12:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the JobSearch plugin to the latest version that addresses the XSS flaw
  • If the update cannot be applied immediately, disable or deactivate the plugin until the fix is available
  • Deploy a web application firewall or a WordPress security plugin that sanitizes user input and blocks malicious scripts

Generated by OpenCVE AI on July 31, 2026 at 12:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Eyecix
Eyecix jobsearch
Wordpress
Wordpress wordpress
Vendors & Products Eyecix
Eyecix jobsearch
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.
Title WordPress JobSearch plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Eyecix Jobsearch
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:53.704Z

Reserved: 2026-06-24T12:46:01.632Z

Link: CVE-2026-57383

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:33.765Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')