CVE-2024-10104
Description
The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
CWE
- (none)
Affected
- Unknown / Jobs for WordPress — v=0 <2.7.8 [affected]
CVSS
- (none)
References
- https://wpscan.com/vulnerability/f0a9c8ae-f2cf-4322-8216-4778b0e37a48/ exploit, vdb-entry, technical-description
Source
cvelistV5-main/cves/2024/10xxx/CVE-2024-10104.json