CVE-2024-0820

CVE-2024-0820: Jobs for WordPress < 2.7.4 - Contributor+ Stored XSS

Vendor Unknown
Product Jobs for WordPress
Published March 18, 2024
Last update March 28, 2025

CVSS base score

—

What the vulnerability does

01Description

The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

Key dates

02Disclosure timeline

March 18, 2024 CVE published
March 28, 2025 Record updated