CVE-2025-58234: WordPress JS Job Manager Plugin <= 2.0.2 - Cross Site Scripting (XSS) Vulnerability
Published Sep 22, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomSky JS Job Manager js-jobs allows Stored XSS.This issue affects JS Job Manager: from n/a through <= 2.0.2.
Affected Software
3 affected components
joomsky JS Job Manager<=2.0.2
WordPress JS Job Manager Plugin<=2.0.2
joomsky Js Job Manager Wordpress<=2.0.2
Event History
Sep 22, 2025
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Oct 28, 58279
Event
via MITRE·11:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-58234?
CVE-2025-58234 has been classified as a high severity vulnerability due to its potential for Stored XSS attacks.
2
How do I fix CVE-2025-58234?
To fix CVE-2025-58234, you should update JoomSky JS Job Manager to version 2.0.3 or later.
3
What type of vulnerability is CVE-2025-58234?
CVE-2025-58234 is categorized as a Cross-site Scripting (XSS) vulnerability.
4
Which versions of JS Job Manager are affected by CVE-2025-58234?
CVE-2025-58234 affects JoomSky JS Job Manager versions up to and including 2.0.2.
5
Can CVE-2025-58234 be exploited by attackers?
Yes, CVE-2025-58234 can be exploited by attackers to execute malicious scripts in the context of a user's browser.