The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This is due to insufficient login restrictions on inactive and pending accounts. This makes it possible for authenticated attackers, with Candidate- and Employer-level access and above, to log in to the site even if their account is inactive or pending.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Wordpress Wordpress wordpress Wp-jobhunt Project Wp-jobhunt Project wp-jobhunt | |
| Vendors & Products | Wordpress Wordpress wordpress Wp-jobhunt Project Wp-jobhunt Project wp-jobhunt | 
Fri, 10 Oct 2025 12:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 10 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This is due to insufficient login restrictions on inactive and pending accounts. This makes it possible for authenticated attackers, with Candidate- and Employer-level access and above, to log in to the site even if their account is inactive or pending. | |
| Title | WP JobHunt <= 7.6 Authenticated (Custom+) Authorization Bypass | |
| Weaknesses | CWE-863 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-10-10T12:01:46.739Z
Reserved: 2025-07-08T22:51:00.471Z
Link: CVE-2025-7374
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-10T12:01:43.202Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-10-10T12:15:37.937
Modified: 2025-10-14T19:36:59.730
Link: CVE-2025-7374
 Redhat
                        Redhat
                    No data.