PT-2025-52550 · WordPress · Wp Jobhunt

Meghnine Islem

·

Published

2025-12-20

·

Updated

2025-12-20

·

CVE-2025-7733

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP JobHunt plugin for WordPress versions prior to 7.8
Description The WP JobHunt plugin for WordPress is susceptible to an Insecure Direct Object Reference issue. This affects versions up to and including 7.7, stemming from a lack of validation on a user-controlled key within the cs update application status callback function. Authenticated attackers with Candidate-level access or higher can exploit this to send a site-generated email containing injected HTML to any user. The vulnerable parameter is a user-controlled key.
Recommendations Update the WP JobHunt plugin to version 7.8 or later.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-7733

Affected Products

Wp Jobhunt