Executive brief
The WP ApplicantStack Jobs Display plugin for WordPress, which is used to display job listings on websites, contains a security flaw. This vulnerability allows users with basic contributor-level access to inject malicious scripts into website pages. When other visitors or administrators view these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.
Technical details
The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via shortcode attributes. The root cause is insufficient input sanitization and output escaping within the plugin's shortcode handling logic. An authenticated attacker with contributor-level permissions or higher can exploit this by embedding malicious JavaScript within a shortcode on a post or page. Because the script is stored on the server, it executes in the browser of any user who visits the affected page. This can lead to session hijacking or unauthorized administrative actions. The vulnerability exists in all versions up to and including 1.1.1.
Affected products
- WP ApplicantStack WP ApplicantStack Jobs Display All versions up to, and including, 1.1.1
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory
References
- https://plugins.trac.wordpress.org/browser/wp-applicantstack-jobs-display/trunk/wp-applicantstack-jobs-display.php
- https://plugins.trac.wordpress.org/browser/wp-applicantstack-jobs-display/trunk/wp-applicantstack-jobs-display.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a66b55e0-1b31-4d5f-bcc1-cfd38b613905?source=cve