Themes Vulnerabilities

InJob < 3.3.8 - Reflected & Persistent XSS

Description

Multiple XSS vulnerabilities have been founded in the 'InJob | Multi-purpose for recruitment WordPress Theme' theme v3.3.6.

Edit (WPScanTeam):
September 16th, 2019 - Envato Contacted
September 16th, 2019 - v3.3.7 released. XSS still present
October 11th, 2019 - Envato contacted again for updates
October 14th, 2019 - Envato Investigating
October 21st, 2019 - v3.3.8 released, fixing the issues.

Proof of Concept

Affects Themes

Fixed in 3.3.8

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
subversa
Submitter
subversa
Verified
Yes

Timeline

Publicly Published
2019-09-16 (about 6 years ago)
Added
2019-10-22 (about 6 years ago)
Last Updated
2021-01-19 (about 5 years ago)

Other