Skip to main content

CVE-2025-7374: WP JobHunt Auth Bypass Vulnerability

CVE-2025-7374 is an authorization bypass flaw in WP JobHunt plugin for WordPress that allows inactive or pending accounts to log in. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-7374 Overview

CVE-2025-7374 is an authorization bypass vulnerability in the WP JobHunt plugin for WordPress, which ships with the JobCareer theme. All versions up to and including 7.6 fail to enforce login restrictions on inactive and pending accounts. Authenticated users holding Candidate- or Employer-level access can authenticate to the site even when their accounts have been marked inactive or are awaiting approval. The weakness is tracked as an incorrect authorization flaw [CWE-863] and affects sites that rely on WP JobHunt's account state model for access control.

Critical Impact

Attackers with previously deactivated or unapproved Candidate or Employer accounts can log in and access authenticated site functionality, undermining moderation and account-suspension controls.

Affected Products

  • WP JobHunt plugin for WordPress, all versions through 7.6
  • JobCareer WordPress theme deployments that bundle WP JobHunt
  • Sites relying on Candidate and Employer account approval or suspension workflows

Discovery Timeline

  • 2025-10-10 - CVE-2025-7374 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in the NVD database

Technical Details for CVE-2025-7374

Vulnerability Analysis

The vulnerability resides in the authentication flow WP JobHunt uses for its custom user roles. WordPress core authentication succeeds for any valid credential pair, and plugins are expected to reject the login when business rules disqualify the account. WP JobHunt does not consistently apply that check for accounts in inactive or pending status. Candidate and Employer accounts that administrators intended to block therefore retain functional access to authenticated endpoints exposed by the plugin and theme.

The impact is limited to features accessible to the two affected roles, such as job applications, candidate profile management, and employer job posting workflows. Because authorization is granted on the basis of role rather than active account state, moderation actions like disabling suspicious employers or deactivating abusive candidates do not fully take effect.

Root Cause

The root cause is missing enforcement of account-state preconditions during login [CWE-863]. The plugin defines account statuses to gate access but does not tie those statuses to an authentication hook such as wp_authenticate_user or an equivalent capability check. As a result, the account state field exists in the data model but is not consulted before the session cookie is issued.

Attack Vector

Exploitation requires valid credentials for a Candidate or Employer account and network access to the WordPress login endpoint. An attacker whose account was disabled, or whose registration is still pending administrator approval, submits the standard login form or wp-login.php request. The plugin accepts the authentication and returns a session, granting access to role-scoped functionality. No additional payloads, chained bugs, or user interaction are required. See the Wordfence Vulnerability Report for the vendor analysis.

Detection Methods for CVE-2025-7374

Indicators of Compromise

  • Successful logins from user accounts whose status field is set to inactive, pending, or an equivalent non-approved value.
  • Job applications, profile edits, or job postings created by accounts that administrators previously suspended.
  • Repeated authentication attempts against wp-login.php from accounts flagged for moderation.

Detection Strategies

  • Query the WordPress user meta table for accounts with non-active status that also have recent session_tokens entries, indicating a live session.
  • Correlate WP JobHunt account-state changes with subsequent authenticated request logs to identify bypassed suspensions.
  • Alert on Candidate or Employer role activity originating from accounts that customer support workflows had marked as deactivated.

Monitoring Recommendations

  • Forward WordPress access logs and authentication events to a centralized log platform for correlation with account-state changes.
  • Enable a WordPress security plugin that records successful logins with user role, account status, and source IP address.
  • Review moderation queues weekly to confirm that pending or disabled accounts show no post-suspension activity.

How to Mitigate CVE-2025-7374

Immediate Actions Required

  • Update WP JobHunt to a version later than 7.6 once the vendor publishes a fix that enforces account-state checks at login.
  • Audit existing Candidate and Employer accounts and force-reset passwords for any account marked inactive or pending.
  • Invalidate active sessions for non-approved accounts by clearing session_tokens user meta entries.

Patch Information

A fixed release addressing the account-status check was not listed in the referenced advisories at the time of publication. Monitor the Wordfence Vulnerability Report and the JobCareer theme page on ThemeForest for vendor updates, and apply the patched WP JobHunt release as soon as it becomes available.

Workarounds

  • Delete or hard-disable inactive and pending accounts instead of relying on the plugin's status flag until a patch is available.
  • Add a custom wp_authenticate_user filter in a site-specific plugin that rejects logins for WP JobHunt accounts whose status meta is not active.
  • Restrict access to wp-login.php with IP allowlisting or an authentication gateway for high-risk deployments.
bash
# Configuration example: block login for non-active WP JobHunt accounts
# Place in a mu-plugin file, e.g. wp-content/mu-plugins/jobhunt-status-gate.php
add_filter('wp_authenticate_user', function ($user) {
    if (is_wp_error($user)) { return $user; }
    $status = get_user_meta($user->ID, 'account_status', true);
    if (in_array($status, ['inactive', 'pending'], true)) {
        return new WP_Error('account_disabled', 'Account is not active.');
    }
    return $user;
}, 99);

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.