WP JobHunt
cpe:2.3:a:wp-jobhunt_project:wp-jobhunt:*:*:*:*:wordpress:*:*
- <= 7.1
A vulnerability allowing authentication bypass has been identified in the WP JobHunt plugin for WordPress, affecting all versions through 7.1. The issue arises because the 'wp_ajax_google_api_login_callback' function fails to properly verify user identity before authentication. This flaw enables unauthenticated attackers to access any candidate's account.
Exploitation of this vulnerability allows unauthenticated attackers to bypass authentication and gain access to arbitrary candidate accounts.
There is no known patch available for this vulnerability. It is recommended to review the vulnerability details thoroughly and consider uninstalling the affected plugin.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.