Authorization Bypass Vulnerability in eyecix JobSearch by eyecix
CVE-2025-49978

4.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
20 June 2025

What is CVE-2025-49978?

An authorization bypass vulnerability has been identified in the eyecix JobSearch plugin, enabling attackers to exploit improperly configured access control levels. This vulnerability allows unauthorized users to bypass intended security measures, potentially leading to unauthorized access to sensitive user information. The issue affects JobSearch versions from n/a through 2.9.0, highlighting the need for prompt updates and security assessments in all implementations.

Affected Version(s)

JobSearch <= 2.9.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.
CVE-2025-49978 : Authorization Bypass Vulnerability in eyecix JobSearch by eyecix