Executive brief
The JobSearch plugin for WordPress, which is used to create job boards and listing sites, contains a security flaw that allows unauthorized users to bypass access controls. This could allow an attacker to view sensitive information that should be restricted to administrators or specific users. If exploited, this could lead to the exposure of private job seeker or employer data, potentially damaging the organization's reputation and violating privacy regulations.
Technical details
A broken access control vulnerability exists in the EyeCix Technologies JobSearch plugin (wp-jobsearch) for WordPress due to missing authorization checks (CWE-862). The flaw affects versions up to and including 3.2.7. A remote, unauthenticated attacker can exploit this vulnerability by sending crafted network requests to bypass intended access restrictions. Successful exploitation allows the attacker to gain unauthorized access to data (Confidentiality: High), though it does not directly permit data modification or service disruption according to the CVSS vector. The issue is resolved in version 3.2.8.
Affected products
- EyeCix Technologies JobSearch <= 3.2.7
Timeline
- 2026-05-16: other: Reported by researcher adhikara13
- 2026-06-03: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date
- 2026-06-17: patched: Patch confirmed available in version 3.2.8