CVE-2025-39537: WordPress Better Customer List for WooCommerce Plugin <= 1.2.3 - Reflected Cross Site Scripting (XSS) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Chimpstudio WP JobHunt allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP JobHunt: from n/a through 7.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blaze Concepts Better Customer List for WooCommerce woo-better-customer-list allows Reflected XSS.This issue affects Better Customer List for WooCommerce: from n/a through <= 1.2.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39537?
The severity of CVE-2025-39537 is considered high due to the potential for unauthorized access.
How do I fix CVE-2025-39537?
To fix CVE-2025-39537, update the WP JobHunt plugin to the latest version that addresses this vulnerability.
What versions of WP JobHunt are affected by CVE-2025-39537?
CVE-2025-39537 affects all versions of WP JobHunt up to and including version 7.1.
What is the impact of CVE-2025-39537?
The impact of CVE-2025-39537 includes potential unauthorized access and manipulation of user data due to improper access control.
Who is the vendor for CVE-2025-39537?
The vendor for CVE-2025-39537 is Chimpstudio, which develops the WP JobHunt plugin.