Impact
The VK Google Job Posting Manager plugin for WordPress suffers from a deserialization flaw that allows untrusted data to create PHP objects. An attacker manipulating the input can be tricked into instantiating arbitrary objects, which can enable execution of malicious code or manipulation of site data. This weakness is classified as CWE-502 and can lead to complete compromise of the affected WordPress site when an attacker achieves sufficient input control.
Affected Systems
Any WordPress installation that has the VK Google Job Posting Manager plugin version 1.3.1 or earlier is affected. The vulnerability applies to all earlier releases due to a lack of release boundary, so any site running a legacy version of the plugin is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. While there is currently no EPSS score available, the lack of listing in CISA KEV suggests no known active exploitation scripts. The likely attack vector requires the attacker to send crafted input through the plugin’s endpoints, which could be achieved remotely via the web interface or through an authenticated user session. Given the nature of object injection, a successful exploit could result in full remote code execution.
OpenCVE Enrichment