CVE-2025-7733
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-7733 is an Insecure Direct Object Reference (IDOR) vulnerability in the WP JobHunt plugin for WordPress, used by the JobCareer theme. It affects all versions up to and including 7.7, allowing authenticated attackers with Candidate-level access or above to send site-generated emails with injected HTML to any user. The vulnerability was published on December 20, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE, Wordfence).

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key) and exists in the cs_update_application_status_callback function, which fails to validate a user-controlled key before processing requests. Because no authorization check is enforced on the object reference, an authenticated attacker can manipulate the key to reference application records belonging to other users and trigger email notifications with attacker-controlled HTML content. The attack vector is network-based, requires low privileges (Candidate-level account), and no user interaction is needed (Wordfence, Red Hat CVE).

Impact

Successful exploitation allows an authenticated attacker to inject arbitrary HTML into site-generated emails sent to any registered user on the platform, enabling phishing, credential harvesting, or social engineering attacks against other users. The integrity impact is rated Low, with no direct confidentiality or availability impact. While the vulnerability does not grant direct system access or data exfiltration, the ability to send spoofed, HTML-injected emails from a trusted site domain can significantly increase the effectiveness of follow-on attacks (Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.026%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid Candidate-level (or higher) account on the target WordPress site, limiting the attacker pool to registered users (Red Hat CVE, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP JobHunt plugin (version ≤ 7.7) with the JobCareer theme, using tools like WPScan or by inspecting page source for theme/plugin indicators.
  2. Account Registration: Register or obtain a Candidate-level account on the target site, as the vulnerable endpoint requires authentication.
  3. Identify Target User: Determine the user ID or application ID of the target recipient (e.g., another applicant, employer, or administrator) by observing application-related requests or enumerating IDs.
  4. Craft Malicious Request: Send a crafted POST request to the cs_update_application_status_callback AJAX endpoint, supplying a manipulated user-controlled key referencing the target's application record and injecting HTML content (e.g., phishing links, fake login forms) into the status update payload.
  5. Email Delivery: The server processes the request without validating the key, triggering a site-generated email to the target user containing the attacker's injected HTML, which may be used for phishing or social engineering (Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing repeated or anomalous POST requests to wp-admin/admin-ajax.php with action=cs_update_application_status_callback from Candidate-level user accounts, especially targeting application IDs not associated with the requesting user.
  • Email: Unexpected site-generated emails sent to users containing unusual HTML, external links, or embedded forms not consistent with normal application status notifications.
  • Application Events: Multiple application status update events triggered by a single user account across many different application records in a short time window.

Mitigation and workarounds

Users should update the WP JobHunt plugin to a version beyond 7.7 that includes proper authorization validation on the cs_update_application_status_callback function. Site administrators should review the plugin vendor's release notes and the JobCareer theme marketplace for patched releases. As a temporary workaround, restricting Candidate-level account registration or disabling the affected AJAX callback via a custom plugin or WAF rule can reduce exposure until a patch is applied (Wordfence, ThemeForest).

Community reactions

The vulnerability was reported and assigned by Wordfence, which published the advisory on December 20, 2025. Coverage has been limited to automated vulnerability aggregators and security databases, with no notable researcher commentary or significant social media discussion identified beyond standard CVE tracking (Wordfence).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15239NONEN/A
  • simple-cloudflare-turnstile
NoYesAug 07, 2026
CVE-2026-15211NONEN/A
  • subscriptions-for-woocommerce
NoYesAug 07, 2026
CVE-2026-15148NONEN/A
  • wp-events-manager
NoYesAug 07, 2026
CVE-2026-16265NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026
CVE-2026-16263NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management