Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7pwr-chwv-jj76

Опубликовано: 20 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on the 'cs_update_application_status_callback' function in all versions up to, and including, 7.7. This makes it possible for authenticated attackers, with Candidate-level access and above, to inject cross-site scripting into the 'status' parameter of applied jobs for any user.

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on the 'cs_update_application_status_callback' function in all versions up to, and including, 7.7. This makes it possible for authenticated attackers, with Candidate-level access and above, to inject cross-site scripting into the 'status' parameter of applied jobs for any user.

EPSS

Процентиль: 13%
0.00043
Низкий

7.6 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.6
nvd
около 2 месяцев назад

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on the 'cs_update_application_status_callback' function in all versions up to, and including, 7.7. This makes it possible for authenticated attackers, with Candidate-level access and above, to inject cross-site scripting into the 'status' parameter of applied jobs for any user.

EPSS

Процентиль: 13%
0.00043
Низкий

7.6 High

CVSS3

Дефекты

CWE-862