Junglewise Threat Intelligence

CVE-2025-69128: EMV JobCareer path traversal and arbitrary file deletion

CVE-2025-69128 · Severity: high · CVSS 8.6 · Published 2026-06-17

Executive brief

The JobCareer theme for WordPress, used for building job board websites, contains a security flaw that allows unauthorized individuals to delete files from the server. An attacker could use this to disable the website or delete critical system files, leading to a total service outage. There is currently no official patch available from the developer to fix this issue.

Technical details

A path traversal vulnerability (CWE-22) exists in the EMV JobCareer theme for WordPress through version 7.3. The flaw allows an unauthenticated remote attacker to manipulate file paths to target and delete arbitrary files on the server. While the CVSS vector indicates no impact on confidentiality or integrity, the impact on availability is high because an attacker can delete critical WordPress core files or configuration files, effectively breaking the site. As of the advisory date, no official patch has been released, and users are advised to use third-party mitigation rules or alternative security measures.

Affected products

  • EMV JobCareer Theme <= 7.3

Timeline

  • 2025-10-16: other: Vulnerability reported by researcher Denver Jackson
  • 2026-05-26: advisory: Initial advisory published by Patchstack
  • 2026-06-17: disclosed: CVE published to NVD

References