CVE-2025-7374: WP JobHunt <= 7.6 Authenticated (Custom+) Authorization Bypass
The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This is due to insufficient login restrictions on inactive and pending accounts. This makes it possible for authenticated attackers, with Candidate- and Employer-level access and above, to log in to the site even if their account is inactive or pending.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7374?
CVE-2025-7374 has a medium severity due to the risk of authorization bypass on inactive and pending accounts.
How do I fix CVE-2025-7374?
To address CVE-2025-7374, upgrade the WP JobHunt plugin to a version later than 7.6.
What causes the vulnerability CVE-2025-7374?
CVE-2025-7374 is caused by insufficient login restrictions on inactive and pending accounts within the WP JobHunt plugin.
Who is affected by CVE-2025-7374?
All users of the WP JobHunt plugin up to version 7.6 are affected by CVE-2025-7374.
Can CVE-2025-7374 be exploited remotely?
Yes, CVE-2025-7374 can be exploited remotely by authenticated attackers due to the authorization bypass.