What the vulnerability does
01Description
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board plugin <= 2.0.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board plugin <= 2.0.0 versions.
Explanation of Vulnerability in Simple Terms
WP Job Portal contains a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts. An attacker with low-level site access can craft a malicious link or page that, when visited by another user, executes JavaScript in their browser. This can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.
What an attacker can do
Inject and execute JavaScript in other users' browsers to steal sessions, credentials, or perform unauthorized actions.
Potential impact on your site
Authenticated users can be compromised; attackers may steal admin sessions or modify site content via victim browsers.
Conditions required to exploit
Attacker needs a low-privilege account on the site; victim must click a malicious link or visit a crafted page.
Key dates
External resources
Related vulnerabilities