Insecure Direct Object Reference in WP JobHunt Plugin for WordPress
CVE-2025-7733
4.3MEDIUM
What is CVE-2025-7733?
The WP JobHunt plugin, utilized within the JobCareer theme on WordPress, contains a flaw that leads to Insecure Direct Object Reference. This vulnerability arises from inadequate validation on a user-controlled key in the 'cs_update_application_status_callback'. It allows authenticated attackers with Candidate-level permissions to exploit the system and send site-generated emails with malicious HTML to any user, potentially compromising user data and system integrity.
Affected Version(s)
WP JobHunt * <= 7.7