Record summary

CVE-2022-1168 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

WP JobSearch

CVE List1.5.1 to < 1.5.1affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2022-1168Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 416 B

GitHub

PoC details
GitHubCVE-2022-1168Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 416 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress WP JobSearch <1.5.1 - Cross-Site ScriptingCVSS 6.1

WordPress WP JobSearch plugin prior to 1.5.1 contains a cross-site scripting vulnerability. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Impact

Attackers can inject malicious JavaScript via XSS in the search_title parameter, potentially stealing user session cookies or performing unauthorized actions.

Remediation

Update to the latest version of the WP JobSearch plugin (1.5.1 or higher) to mitigate the XSS vulnerability.

WeaknessesCWE-79
AuthorsAkincibor
Template tagscvecve2022wp-jobsearch"wpscanwp-pluginwpwordpressxsseyecixvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:eyecix:jobsearch_wp_job_board:*:*:*:*:*:wordpress:*:*
Google: inurl:"wp-content/plugins/wp-jobsearch"

Source: ProjectDiscovery

References

3