CVE-2025-6585: WP JobHunt <= 7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Account Deletion
The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.2 via the csremoveprofilecallback() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete accounts of other users including admins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6585?
CVE-2025-6585 has a high severity rating due to its potential for exploitation by authenticated attackers.
How do I fix CVE-2025-6585?
To fix CVE-2025-6585, update the WP JobHunt plugin to version 7.3 or later.
What type of vulnerability is CVE-2025-6585?
CVE-2025-6585 is classified as an Insecure Direct Object Reference vulnerability.
Who is affected by CVE-2025-6585?
All versions of the WP JobHunt plugin up to and including version 7.2 are affected by CVE-2025-6585.
What can attackers do with CVE-2025-6585?
Attackers can manipulate user-controlled keys to access or modify profiles, potentially leading to unauthorized actions.