
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-7733 is an Insecure Direct Object Reference (IDOR) vulnerability in the WP JobHunt plugin for WordPress, used by the JobCareer theme. It affects all versions up to and including 7.7, allowing authenticated attackers with Candidate-level access or above to send site-generated emails with injected HTML to any user. The vulnerability was published on December 20, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE, Wordfence).
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key) and exists in the cs_update_application_status_callback function, which fails to validate a user-controlled key before processing requests. Because no authorization check is enforced on the object reference, an authenticated attacker can manipulate the key to reference application records belonging to other users and trigger email notifications with attacker-controlled HTML content. The attack vector is network-based, requires low privileges (Candidate-level account), and no user interaction is needed (Wordfence, Red Hat CVE).
Successful exploitation allows an authenticated attacker to inject arbitrary HTML into site-generated emails sent to any registered user on the platform, enabling phishing, credential harvesting, or social engineering attacks against other users. The integrity impact is rated Low, with no direct confidentiality or availability impact. While the vulnerability does not grant direct system access or data exfiltration, the ability to send spoofed, HTML-injected emails from a trusted site domain can significantly increase the effectiveness of follow-on attacks (Wordfence).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.026%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid Candidate-level (or higher) account on the target WordPress site, limiting the attacker pool to registered users (Red Hat CVE, Wordfence).
cs_update_application_status_callback AJAX endpoint, supplying a manipulated user-controlled key referencing the target's application record and injecting HTML content (e.g., phishing links, fake login forms) into the status update payload.wp-admin/admin-ajax.php with action=cs_update_application_status_callback from Candidate-level user accounts, especially targeting application IDs not associated with the requesting user.Users should update the WP JobHunt plugin to a version beyond 7.7 that includes proper authorization validation on the cs_update_application_status_callback function. Site administrators should review the plugin vendor's release notes and the JobCareer theme marketplace for patched releases. As a temporary workaround, restricting Candidate-level account registration or disabling the affected AJAX callback via a custom plugin or WAF rule can reduce exposure until a patch is applied (Wordfence, ThemeForest).
The vulnerability was reported and assigned by Wordfence, which published the advisory on December 20, 2025. Coverage has been limited to automated vulnerability aggregators and security databases, with no notable researcher commentary or significant social media discussion identified beyond standard CVE tracking (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."