Impact
The WP JobHunt plugin contains a missing validation on a user‑controlled key in the "cs_update_application_status_callback" routine, creating an insecure direct object reference. Authenticated users with Candidate level or higher privileges can exploit this flaw to send a site‑generated email that includes injected HTML to any other user. This could enable phishing, lure users into executing malicious scripts, or create spoofed communications that appear legitimate to recipients.
Affected Systems
Any WordPress site running WP JobHunt version 7.7 or earlier, including installations that use the JobCareer theme, is affected. The vulnerability exists in the plugin itself and does not depend on other components beyond the WordPress environment.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact, and an EPSS score of less than 1 – the exploitation probability is minimal. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated request to the plugin’s AJAX callback, requiring the attacker to be logged in with Candidate or higher privileges. The lack of observable widespread exploitation or wealth of public exploits further limits the risk to most environments, but any site receiving uncontrolled emails should consider remediation promptly.
OpenCVE Enrichment