Cross-Site Request Forgery in Career Section Plugin for WordPress
CVE-2025-14868

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 April 2026

What is CVE-2025-14868?

The Career Section plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF), which can lead to path traversal and arbitrary file deletion. This vulnerability exists due to the absence of nonce validation and inadequate checks on file paths during the delete action of the 'appform_options_page_html' function. Attackers can exploit this weakness to send fraudulent requests that, if an administrator is deceived into clicking a malicious link, could result in the unauthorized deletion of files on the server.

Affected Version(s)

Career Section 0 <= 1.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivan Cese
.