CVE-2026-18063
The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- EPSS probability
- 0.20%
- CWE
- CWE-79
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- blueglassch Job Postings
Weakness type
Related vulnerabilities
- CVE-2026-78252 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-90943 — parallax filament-comments through 3.0.0 Stored XSS via Comment Body
- CVE-2026-90561 — Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG
- CVE-2026-89256 — AVideo Bookmark Plugin Stored XSS via Chapter Names
- CVE-2026-89255 — AVideo LoginControl Stored XSS via PGP Public Key
- CVE-2026-15639 — Reflected Cross-Site Scripting
- CVE-2026-45143 — Chamilo LMS: Student-to-admin stored XSS in private messages via v-html
- CVE-2026-77615 — Paella Player: Stored XSS via caption cue text