WordPress · Wp Jobhunt · CVE-2025-7374
**Name of the Vulnerable Software and Affected Versions**
WP JobHunt plugin for WordPress versions prior to 7.7
**Description**
The WP JobHunt plugin for WordPress, used with the JobCareer theme, has a flaw that allows authorized users with Candidate- or Employer-level access, or higher, to log in even if their account is inactive or pending. This is caused by inadequate login restrictions on these account states, resulting in an authorization bypass.
**Recommendations**
Update to version 7.7 or later.