PT-2025-52551 · WordPress · Wp Jobhunt

·

CVE-2025-7782

·

Published

2025-12-20

·

Updated

2025-12-20

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions WP JobHunt plugin for WordPress versions prior to 7.8
Description The WP JobHunt plugin for WordPress is susceptible to unauthorized data modification. A missing capability check within the cs update application status callback function allows authenticated attackers with Candidate-level access or higher to inject cross-site scripting into the status parameter of applied jobs for any user.
Recommendations Update the WP JobHunt plugin to version 7.8 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7782

Affected Products

Wp Jobhunt