First published: Fri Oct 18 2024(Updated: )
The MAS Companies For WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.13. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Job Manager | <1.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9206 has a severity rating that requires immediate attention due to its potential for allowing reflected cross-site scripting attacks.
To fix CVE-2024-9206, you should upgrade the MAS Companies For WP Job Manager plugin to version 1.0.14 or later.
CVE-2024-9206 is classified as a reflected cross-site scripting (XSS) vulnerability.
All users of the MAS Companies For WP Job Manager plugin for WordPress up to version 1.0.13 are affected by CVE-2024-9206.
Yes, CVE-2024-9206 can be exploited by unauthenticated attackers due to improper input handling in the plugin.