CVE-2025-7781: WP JobHunt <= 7.6 - Authenticated (Candidate+) Stored Cross-Site Scripting via ‘cs_job_title’
The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Stored Cross-Site Scripting via the ‘csjobtitle’ parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Candidate-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7781?
CVE-2025-7781 has a medium severity rating due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-7781?
To fix CVE-2025-7781, update the WP JobHunt plugin to version 7.7 or later, which addresses the input sanitization issues.
Who is affected by CVE-2025-7781?
All users of the WP JobHunt plugin for WordPress, especially those using versions up to and including 7.6, are affected by CVE-2025-7781.
What happens if I don't fix CVE-2025-7781?
If CVE-2025-7781 is not fixed, attackers may exploit the vulnerability to execute malicious scripts in the context of the user’s session.
Is CVE-2025-7781 easy to exploit?
Yes, CVE-2025-7781 is considered easy to exploit due to its reliance on insufficient input sanitization.