CVE-2025-49978: WordPress JobSearch plugin < 3.0.6 - Insecure Direct Object References (IDOR) Vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobSearch: from n/a through 2.9.0.
Other sources
Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch wp-jobsearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through < 3.0.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49978?
CVE-2025-49978 has a high severity rating due to the potential for unauthorized access through incorrect access control settings.
How do I fix CVE-2025-49978?
To fix CVE-2025-49978, ensure correct configuration of access control settings and consider updating to a patched version of the software.
What versions are affected by CVE-2025-49978?
CVE-2025-49978 affects Eyecix JobSearch and WordPress JobSearch plugin versions up to and including 2.9.0.
What type of vulnerability is CVE-2025-49978?
CVE-2025-49978 is classified as an authorization bypass vulnerability.
Who is impacted by CVE-2025-49978?
Any users of Eyecix JobSearch or WordPress JobSearch plugin versions 2.9.0 and below may be impacted by CVE-2025-49978.