CVE-2024-47394: WordPress WP JobSearch plugin <= 2.5.9 - Reflected Cross Site Scripting (XSS) vulnerability
Published Oct 5, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Reflected XSS.This issue affects JobSearch: from n/a through <= 2.5.9.
Affected Software
1 affected component
Eyecix WP JobSearch<=2.5.9
Remediation
Information
Update to 2.6.1 or a higher version.
Event History
Oct 5, 2024
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47394?
CVE-2024-47394 has a medium severity level due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2024-47394?
To fix CVE-2024-47394, update eyecix JobSearch to version 2.6.0 or later.
3
What versions are affected by CVE-2024-47394?
CVE-2024-47394 affects eyecix JobSearch from version n/a up to and including 2.5.9.
4
What is the nature of the vulnerability in CVE-2024-47394?
CVE-2024-47394 is an improper neutralization of input during web page generation, leading to a reflected XSS vulnerability.
5
Who is impacted by CVE-2024-47394?
Users of eyecix JobSearch and the WP JobSearch plugin from version n/a to 2.5.9 are impacted by CVE-2024-47394.