Access violation vulnerability in WP JobHunt 7.1

The WP JobHunt plugin for WordPress has a security issue that allows unauthorized users to take over someone else’s account. This can happen because the plugin does not check a user’s identity before changing their password. This means that attackers who are not logged in can change anyone’s password, even an administrator’s, and then use that to access their account.

Detected in:

wp-jobhunt fixed vulnerable versions: >= * <= 7.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.