Impact
The flaw is an access‑control weakness that enables an attacker to delete any content managed by the JobHunt Job Alerts plugin. Because the plugin’s delete operations lack proper authorization checks, a malicious actor can remove job listings, administrative posts, or other plugin data, effectively erasing published job offers and potentially disrupting site operations. This issue is classified as CWE‑862.
Affected Systems
WordPress sites that have the Chimpstudio JobHunt Job Alerts plugin installed with a version of 3.6 or earlier are impacted. Sites running newer versions that are not listed as vulnerable are presumed safe, but the CVE does not enumerate a fixed release.
Risk and Exploitability
With a CVSS score of 8.2 the vulnerability is rated high severity. The EPSS score of less than 1 % indicates that exploitation is currently unlikely, and the flaw is not present in the CISA KEV catalog. The likely attack vector is through the web interface; an attacker can craft a request to the plugin’s delete endpoint without needing elevated privileges. If an attacker can reach the endpoint, content can be deleted, leading to loss of job listings and site disruption.
OpenCVE Enrichment
EUVD