CVE-2025-7782

🟡 Monitoruj

Brak weryfikacji uprawnień w WP JobHunt pozwala na wstrzyknięcie XSS przez uwierzytelnionych atakujących.

CVSS
7.6
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on the 'cs_update_application_status_callback' function in all versions up to, and including, 7.7. This makes it possible for authenticated attackers, with Candidate-level access and above, to inject cross-site scripting into the 'status' parameter of applied jobs for any user.

xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.6
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2025-12-20 14:16:03 UTC
Ostatnia modyfikacja (NVD)2026-10-05 18:10:00 UTC
Referencje