Description
Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
Published: 2026-10-05
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution via Object Injection
Action: Immediate Patch
AI Analysis

Impact

The VK Google Job Posting Manager plugin for WordPress suffers from a deserialization flaw that allows untrusted data to create PHP objects. An attacker manipulating the input can be tricked into instantiating arbitrary objects, which can enable execution of malicious code or manipulation of site data. This weakness is classified as CWE-502 and can lead to complete compromise of the affected WordPress site when an attacker achieves sufficient input control.

Affected Systems

Any WordPress installation that has the VK Google Job Posting Manager plugin version 1.3.1 or earlier is affected. The vulnerability applies to all earlier releases due to a lack of release boundary, so any site running a legacy version of the plugin is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. While there is currently no EPSS score available, the lack of listing in CISA KEV suggests no known active exploitation scripts. The likely attack vector requires the attacker to send crafted input through the plugin’s endpoints, which could be achieved remotely via the web interface or through an authenticated user session. Given the nature of object injection, a successful exploit could result in full remote code execution.

Generated by OpenCVE AI on October 5, 2026 at 20:46 UTC.

Remediation

Vendor Solution

Update the WordPress VK Google Job Posting Manager plugin to the latest available version (at least 1.3.2).


OpenCVE Recommended Actions

  • Update the VK Google Job Posting Manager plugin to version 1.3.2 or later to remove the deserialization flaw.
  • Disable the plugin if an update is not immediately possible to eliminate the attack surface.
  • Restrict administrative access to the plugin’s settings and endpoints to trusted admin accounts only.

Generated by OpenCVE AI on October 5, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
Title WordPress VK Google Job Posting Manager plugin <= 1.3.1 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T19:00:11.317Z

Reserved: 2026-09-26T00:17:50.215Z

Link: CVE-2026-100511

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T20:17:07.177

Modified: 2026-10-05T20:17:07.177

Link: CVE-2026-100511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:00:21Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data