WP JobHunt
cpe:2.3:a:wp-jobhunt_project:wp-jobhunt:*:*:*:*:wordpress:*:*
- <= 7.6
A vulnerability allowing authorization bypass has been identified in the WP JobHunt plugin for WordPress, specifically in versions through 7.6. This issue arises from inadequate login restrictions on inactive and pending accounts, enabling authenticated attackers with Candidate or Employer-level access to log in despite their accounts being inactive or pending.
Exploitation of this vulnerability allows authenticated users to bypass account status restrictions, potentially leading to unauthorized access or actions on the site.
Users can update to WP JobHunt version 7.7 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.