The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This is due to insufficient login restrictions on inactive and pending accounts. This makes it possible for authenticated attackers, with Candidate- and Employer-level access and above, to log in to the site even if their account is inactive or pending.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wp-jobhunt Project Wp-jobhunt Project wp-jobhunt |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wp-jobhunt Project Wp-jobhunt Project wp-jobhunt |
Fri, 10 Oct 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This is due to insufficient login restrictions on inactive and pending accounts. This makes it possible for authenticated attackers, with Candidate- and Employer-level access and above, to log in to the site even if their account is inactive or pending. | |
| Title | WP JobHunt <= 7.6 Authenticated (Custom+) Authorization Bypass | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-10-10T12:01:46.739Z
Reserved: 2025-07-08T22:51:00.471Z
Link: CVE-2025-7374
Updated: 2025-10-10T12:01:43.202Z
Status : Awaiting Analysis
Published: 2025-10-10T12:15:37.937
Modified: 2025-10-14T19:36:59.730
Link: CVE-2025-7374
No data.