Junglewise Threat Intelligence

CVE-2026-54186: EyeCix JobSearch unauthenticated SQL injection

CVE-2026-54186 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: EyeCix Technologies JobSearch. Vendors: EyeCix Technologies.

Executive brief

The JobSearch plugin for WordPress, which is used to create job boards and listing sites, contains a critical security flaw. An unauthenticated attacker can remotely interact with the website's database to steal sensitive information or disrupt operations. This vulnerability is considered high priority as it can be exploited without any user interaction or login credentials.

Technical details

A SQL injection vulnerability exists in the EyeCix JobSearch plugin (wp-jobsearch) for WordPress in versions up to and including 3.2.9. The flaw is caused by improper neutralization of special elements used in SQL commands (CWE-89), allowing an unauthenticated attacker to send malicious payloads over the network. Successful exploitation enables the attacker to directly interact with the database, potentially leading to the exfiltration of sensitive data or partial impact on service availability. The vulnerability has been addressed in version 3.3.0.

Affected products

  • EyeCix Technologies JobSearch <= 3.2.9

Timeline

  • 2026-04-23: other: Reported by Nguyen Ba Khanh
  • 2026-06-16: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date
  • 2026-06-17: patched: Version 3.3.0 released to address the issue

References

Related threats