CVE-2025-52798: WordPress JobSearch plugin < 3.0.6 - Reflected Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch allows Reflected XSS. This issue affects JobSearch: from n/a through 2.9.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Reflected XSS.This issue affects JobSearch: from n/a through < 3.0.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52798?
CVE-2025-52798 is rated as a critical vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-52798?
To mitigate CVE-2025-52798, upgrade the eyecix JobSearch plugin to version 2.9.1 or later.
What specific versions are affected by CVE-2025-52798?
CVE-2025-52798 affects eyecix JobSearch versions up to and including 2.9.0.
What type of attack does CVE-2025-52798 expose systems to?
CVE-2025-52798 exposes systems to reflected cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
What products are impacted by CVE-2025-52798?
CVE-2025-52798 impacts both eyecix JobSearch and WordPress JobSearch versions up to 2.9.0.