The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This is due to insufficient login restrictions on inactive and pending accounts. This makes it possible for authenticated attackers, with Candidate- and Employer-level access and above, to log in to the site even if their account is inactive or pending.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Oct 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 10 Oct 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This is due to insufficient login restrictions on inactive and pending accounts. This makes it possible for authenticated attackers, with Candidate- and Employer-level access and above, to log in to the site even if their account is inactive or pending. | |
Title | WP JobHunt <= 7.6 Authenticated (Custom+) Authorization Bypass | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-10-10T11:17:08.050Z
Updated: 2025-10-10T12:01:46.739Z
Reserved: 2025-07-08T22:51:00.471Z
Link: CVE-2025-7374

Updated: 2025-10-10T12:01:43.202Z

Status : Received
Published: 2025-10-10T12:15:37.937
Modified: 2025-10-10T12:15:37.937
Link: CVE-2025-7374

No data.