CVE-2024-0820

CVE-2024-0820: Jobs for WordPress < 2.7.4 - Contributor+ Stored XSS

Vendor Unknown
Product Jobs for WordPress
Published March 18, 2024
Last update March 28, 2025

CVSS base score

What the vulnerability does

01Description

The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

Key dates

02Disclosure timeline

March 18, 2024 CVE published
March 28, 2025 Record updated