Junglewise Threat Intelligence

CVE-2026-57383: eyecix JobSearch Stored XSS in wp-jobsearch

CVE-2026-57383 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

The JobSearch plugin for WordPress, which provides job board and recruitment functionality, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could execute code in their browser, potentially leading to unauthorized actions or the theft of sensitive session information. This vulnerability could be used to deface the site or redirect users to malicious third-party websites.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the eyecix JobSearch (wp-jobsearch) plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw allows an unauthenticated remote attacker to inject malicious scripts into the application. Successful exploitation requires a privileged user to perform an action, such as clicking a malicious link or visiting a crafted page (User Interaction). Once triggered, the injected script executes in the context of the victim's browser, potentially allowing for session hijacking or unauthorized administrative actions. The issue is fixed in version 3.3.0.

Affected products

  • eyecix JobSearch (wp-jobsearch) <= 3.2.9

Timeline

  • 2026-04-23: other: Reported by Nguyen Ba Khanh
  • 2026-07-07: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD

References