Executive brief
The Jobify theme for WordPress, which is used to create job board websites, contains a security flaw that allows attackers to inject malicious scripts into the site. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This vulnerability can be exploited by anyone on the internet without needing an account on the affected website.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Astoundify Jobify theme for WordPress (versions 4.3.2 and below) due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's browser session. Exploitation requires a user to interact with a malicious link or crafted page (User Interaction: Required). Successful exploitation can lead to session hijacking, unauthorized actions on behalf of the user, or the delivery of further browser-based exploits. The issue is resolved in version 4.3.3.
Affected products
- Astoundify Jobify <= 4.3.2
Timeline
- 2026-04-27: other: Reported by João Pedro S Alcântara (Kinorth)
- 2026-06-29: disclosed: Vulnerability published by Patchstack and NVD
- 2026-06-29: patched: Version 4.3.3 released to address the vulnerability