CVE-2025-49978Authorization Bypass Through User-Controlled Key in Jobsearch

Severity
5.5MEDIUM
No vector
EPSS
0.1%
top 69.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 20

Description

Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch wp-jobsearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through < 3.0.6.

Affected Packages1 packages

CVEListV5eyecix/jobsearch3.0.6

🔴Vulnerability Details

2
GHSA
GHSA-3f52-4448-3p36: Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Le2025-06-20
CVEList
WordPress JobSearch plugin < 3.0.6 - Insecure Direct Object References (IDOR) Vulnerability2025-06-20

📋Vendor Advisories

1
Microsoft
gso: fix udp gso fraglist segmentation after pull from frag_list2024-10-08
CVE-2025-49978 — Eyecix Jobsearch vulnerability | cvebase