PT-2025-21704 · WordPress · Chimpstudio Wp Jobhunt

Bonds

·

Published

2025-05-16

·

Updated

2025-05-16

·

CVE-2025-39537

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Chimpstudio WP JobHunt versions n/a through 7.1
Description: The issue affects Chimpstudio WP JobHunt, allowing exploitation of incorrectly configured access control security levels through an Authorization Bypass Through User-Controlled Key vulnerability. This enables exploiting incorrectly configured access control security levels.
Recommendations: For Chimpstudio WP JobHunt versions n/a through 7.1, update to a version that addresses the Authorization Bypass Through User-Controlled Key vulnerability to prevent exploitation of incorrectly configured access control security levels.

Fix

IDOR

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-39537

Affected Products

Chimpstudio Wp Jobhunt