Impact
The vulnerability involves unsanitized deserialization of untrusted data in PickPlugins Job Board Manager, enabling PHP Object Injection. An attacker can craft a malicious payload that is deserialized by the plugin, potentially allowing arbitrary code execution, data tampering, or unauthorized access. This weakness corresponds to CWE‑502, as the application processes serialized input without proper validation.
Affected Systems
The affected product is the WordPress Job Board Manager plugin from PickPlugins. All versions up to and including 2.1.61 are impacted. No later releases were listed as affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. However, if exploited, the injection could lead to full remote code execution on the host running WordPress, making it a serious threat for any site that allows untrusted input to the plugin [inferred].
OpenCVE Enrichment
EUVD