PT-2026-33281 · WordPress · Career Section

Ivan Cese

·

Published

2026-04-16

·

Updated

2026-04-16

·

CVE-2025-14868

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Career Section plugin for WordPress versions prior to 1.7
Description The plugin is susceptible to Cross-Site Request Forgery (CSRF), a flaw where an attacker tricks a logged-in user into executing unwanted actions. This issue leads to Path Traversal and Arbitrary File Deletion due to missing nonce validation and insufficient file path validation within the appform options page html() function. Unauthenticated attackers can delete arbitrary files on the server by inducing a site administrator to click a forged link.
Recommendations Update the plugin to a version later than 1.6. As a temporary workaround, restrict access to the appform options page html() function to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-14868

Affected Products

Career Section