Impact
Deserialization of untrusted data in the NooTheme Jobica Core WordPress plugin allows attackers to inject malicious PHP objects. This object injection falls under CWE‑502 and can permit the execution of arbitrary code inside the web site, jeopardizing confidentiality, integrity, and availability. The vulnerability can lead to a full takeover of a vulnerable WordPress site.
Affected Systems
The NooTheme Jobica Core plugin for WordPress, versions up to and including 1.4.1, is vulnerable. The issue applies to any WordPress installation that uses a vulnerable release of the plugin; no specific PHP or OS versions are mentioned, so the flaw is broad in scope.
Risk and Exploitability
The CVSS score of 8.8 classifies the risk as high, and the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known active exploits at this time. Nonetheless, the flaw permits remote code execution when the plugin deserializes data submitted over the web interface, making the attack vector remote via the website.
OpenCVE Enrichment