CVE-2024-10105
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Published Mar 25, 2025
Updated: Apr 2, 2025
CWE ID 79
Summary
CVE-2024-10105 is a vulnerability affecting the Job Postings WordPress plugin before version 2.7.11. This issue allows high privilege users, such as contributors, to execute Stored Cross-Site Scripting attacks. Despite the disallowing of the unfiltered_html capability, these attacks can still be performed due to the plugin's failure to sanitize and escape certain settings. In multisite setups, this vulnerability poses a significant risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.