Impact
The WP JobHunt plugin for WordPress is vulnerable to an insecure direct object reference because the cs_remove_profile_callback() function does not validate a user-controlled key. This flaw permits authenticated users with Subscriber level or higher to delete any other user’s account, including administrators, thus tampering with legitimate user data and potentially disabling critical application functionality.
Affected Systems
WordPress users running the WP JobHunt plugin at version 7.2 or earlier are affected. The vulnerability exists in all releases up to and including 7.2 and is specific to the WP JobHunt plugin for WordPress.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity impact. The EPSS score of < 1% suggests a very low current exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector requires an authenticated session, as the flaw is triggered through the cs_remove_profile_callback endpoint exposed to users with Subscriber or higher privileges. An attacker who can craft a request with the vulnerable key can delete target accounts without additional privileged access.
OpenCVE Enrichment
EUVD