CVE-2021-39329: JobBoardWP – Job Board Listings and Submissions <= 1.0.7 Authenticated Stored Cross-Site Scripting
The JobBoardWP WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-metabox.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0.7. This affects multi-site installations where unfilteredhtml is disabled for administrators, and sites where unfilteredhtml is disabled.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-39329?
CVE-2021-39329 refers to a vulnerability in the JobBoardWP WordPress plugin that allows for stored cross-site scripting (XSS) attacks.
What is the severity of CVE-2021-39329?
The severity of CVE-2021-39329 is medium with a CVSS score of 4.8.
How does CVE-2021-39329 affect the JobBoardWP plugin?
CVE-2021-39329 affects the JobBoardWP plugin by enabling attackers with administrative user access to inject arbitrary web scripts.
Which version of the JobBoardWP plugin is affected by CVE-2021-39329?
CVE-2021-39329 affects JobBoardWP plugin version 1.0.7 and below.
How can I fix CVE-2021-39329 in my JobBoardWP plugin?
To fix CVE-2021-39329 in the JobBoardWP plugin, it is recommended to update to the latest version that includes a patch for this vulnerability.