PT-2025-41557 · WordPress+1 · Wp Jobhunt+1

Meghnine Islem

·

Published

2025-10-10

·

Updated

2025-10-10

·

CVE-2025-7374

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP JobHunt plugin for WordPress versions prior to 7.7
Description The WP JobHunt plugin for WordPress, used with the JobCareer theme, has a flaw that allows authorized users with Candidate- or Employer-level access, or higher, to log in even if their account is inactive or pending. This is caused by inadequate login restrictions on these account states, resulting in an authorization bypass.
Recommendations Update to version 7.7 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-7374

Affected Products

Jobcareer
Wp Jobhunt