Stored Cross-Site Scripting in Jobify Plugin for WordPress
CVE-2025-8318
6.4MEDIUM
What is CVE-2025-8318?
The Jobify plugin for WordPress has a vulnerability that allows stored cross-site scripting (XSS) through the 'keyword' parameter. This weakness arises from inadequate input sanitization and output escaping, enabling authenticated attackers with Contributor-level access or higher to inject harmful web scripts. When users access the compromised page, these scripts can execute, posing significant risks to user data and site integrity.
Affected Version(s)
Jobify * <= 1.4.4