vulnerability

WordPress Theme: careerfy: CVE-2022-1169: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Jun 3, 2020
Added
Dec 8, 2025
Modified
Dec 8, 2025

Description

The Careerfy theme plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Solution

careerfy-theme-cve-2022-1169
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.