First published: Mon Mar 18 2024(Updated: )
The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Jobs | <2.7.4 | |
BlueGlass Jobs for WordPress | <2.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0820 has a medium severity rating due to its potential for Stored Cross-Site Scripting attacks.
To fix CVE-2024-0820, update the Jobs for WordPress plugin to version 2.7.4 or later.
Users with WordPress installations running the Jobs for WordPress plugin versions prior to 2.7.4 are affected by CVE-2024-0820.
CVE-2024-0820 allows users with contributor roles to execute Stored Cross-Site Scripting attacks.
Yes, versions 2.7.4 and above of the Jobs for WordPress plugin are safe from the vulnerabilities associated with CVE-2024-0820.