Input validation vulnerability in WP JobHunt 7.2

The WP JobHunt plugin for WordPress has a security issue that can affect all versions up to 7.2. This vulnerability is called Insecure Direct Object Reference and is caused by a function called cs_remove_profile_callback(). The problem is that this function does not check for valid information from the user before making changes. This means that someone who is logged in and has at least Subscriber access can delete the accounts of other users, including administrators.

Detected in:

wp-jobhunt fixed vulnerable versions: >= * <= 7.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.