CVE-2021-24421: WP JobSearch < 1.7.4 - Authenticated Stored XSS
Published Jul 12, 2021
·Updated
The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue
Affected Software
1 affected component
Eyecix JobSearch WP Job Board WordPress<1.7.4
Event History
Jul 12, 2021
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24421?
The severity of CVE-2021-24421 is medium with a CVSS score of 5.4.
2
How does CVE-2021-24421 impact users?
CVE-2021-24421 impacts users by allowing low privilege users to use JavaScript payloads, leading to a Stored Cross-Site Scripting issue.
3
What version of the WP JobSearch WordPress plugin is affected by CVE-2021-24421?
The WP JobSearch WordPress plugin version up to exclusive 1.7.4 is affected by CVE-2021-24421.