CVE-2024-10104

CVE-2024-10104: Jobs for WordPress < 2.7.8 - Contributor+ Stored XSS

Vendor Unknown
Product Jobs for WordPress
Published November 15, 2024
Last update November 15, 2024

CVSS base score

What the vulnerability does

01Description

The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

Key dates

02Disclosure timeline

November 15, 2024 CVE published
November 15, 2024 Record updated