CVE-2025-24781: WordPress WPJobBoard plugin <= 5.10.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WPJobBoard allows Reflected XSS. This issue affects WPJobBoard: from n/a through 5.10.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WPJobBoard wpjobboard allows Reflected XSS.This issue affects WPJobBoard: from n/a through <= 5.10.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24781?
CVE-2025-24781 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-24781?
To mitigate CVE-2025-24781, update the NotFound WPJobBoard plugin to version 5.10.1 or later.
What versions of WPJobBoard are affected by CVE-2025-24781?
CVE-2025-24781 affects all versions of WPJobBoard from n/a up to and including 5.10.1.
What type of attack can be executed due to CVE-2025-24781?
CVE-2025-24781 allows for reflected cross-site scripting attacks, enabling attackers to execute malicious scripts in users' browsers.
Is CVE-2025-24781 confirmed to be exploited in the wild?
As of now, there is no confirmed report of CVE-2025-24781 being actively exploited in the wild.