PT-2022-13684 · WordPress · Careerup Careerup Wordpress Theme
Daniel Ruf
+1
·
Published
2022-04-04
·
Updated
2022-04-11
·
CVE-2022-1167
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CareerUp Careerup WordPress theme versions prior to 2.3.1
Description
The issue is related to unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities. These vulnerabilities can be exploited via the
filter parameters.Recommendations
For CareerUp Careerup WordPress theme versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the
filter parameters to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Careerup Careerup Wordpress Theme