Executive brief
WPJobster is a WordPress theme used to build service marketplace websites similar to Fiverr. A security flaw allows unauthorized individuals to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer data, user credentials, or business information, potentially resulting in a total compromise of the platform's data.
Technical details
A SQL injection vulnerability exists in the WPJobster theme for WordPress (versions <= 6.3.5) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to unauthenticated remote attackers over the network, requiring no user interaction. By sending specially crafted requests, an attacker can bypass security controls to read sensitive information from the database or potentially impact service availability. As of the advisory date, no official patch has been released by the developer, though third-party mitigation rules are available.
Affected products
- Jobster Marketplace WPJobster <= 6.3.5
Timeline
- 2025-11-16: other: Vulnerability reported by researcher 0xd4rk5id3
- 2026-01-27: advisory: Initial advisory published by Patchstack
- 2026-06-17: disclosed: CVE published to NVD