Impact
The WP ApplicantStack Jobs Display plugin contains a stored cross‑site scripting flaw that allows an authenticated contributor or higher to inject arbitrary JavaScript into pages via shortcode attributes. Because the input is not properly sanitized or escaped, the malicious script is stored in the database and executed whenever any user views the affected page. This can lead to theft of cookies, session hijacking, and the execution of additional malicious actions in the context of each visitor’s browser. The vulnerability compromises confidentiality and potentially the integrity of user sessions, with the attack affecting all users who load the compromised pages.
Affected Systems
The flaw affects all releases of the jdm‑labs WP ApplicantStack Jobs Display plugin up to and including version 1.1.1. No newer versions are mentioned in the advisory, so any installation using 1.1.1 or older is vulnerable.
Risk and Exploitability
With a CVSS score of 6.4 the vulnerability is considered moderate in severity. The EPSS score is not available, so the current exploitation likelihood cannot be quantified, but the flaw is listed as not part of the CISA KEV catalog. Execution requires an authenticated account with contributor privileges; the attacker would need to know the shortcode syntax to embed the malicious attribute. Once the script is stored, it is automatically executed for any site visitor until the code is removed or the plugin is upgraded.
OpenCVE Enrichment