Executive brief
WPJobster, a WordPress theme used for building service marketplace websites, contains a security flaw that allows attackers to execute malicious scripts in a user's browser. An attacker could use this to redirect visitors to fraudulent websites, steal session information, or display unauthorized advertisements. This vulnerability can be triggered without an account, though it requires a victim to click a specially crafted link.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the WPJobster theme for WordPress (versions 6.3.5 and below) due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's browser session. Exploitation requires the attacker to trick a user into interacting with a malicious link or visiting a crafted page. As of the advisory date, no official patch has been released by the vendor, though third-party mitigation rules are available.
Affected products
- Jobster Marketplace WPJobster <= 6.3.5
Timeline
- 2025-11-16: other: Vulnerability reported by researcher 0xd4rk5id3
- 2026-01-27: advisory: Initial disclosure by Patchstack
- 2026-06-17: disclosed: CVE published to NVD