Impact
The vulnerability is an unauthenticated PHP Object Injection in the JobSearch plugin. An attacker can inject crafted serialized data that the plugin processes without proper validation, allowing instantiation of arbitrary PHP objects. This flaw can lead to arbitrary code execution, placement of malicious files, or other actions that compromise the confidentiality, integrity, and availability of the affected WordPress site. The impact is substantial because the attacker does not need authentication to exploit the flaw.
Affected Systems
The issue affects eyecix’s JobSearch plugin for WordPress versions 3.2.0 and earlier. Any WordPress site running a vulnerable version of this plugin is at risk until the plugin is upgraded beyond 3.2.0.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified, but the flaw is fully unauthenticated and can be triggered remotely via web requests. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, yet its high score and remote nature mean it is a top priority for remediation.
OpenCVE Enrichment