Executive brief
JobSearch is a popular WordPress plugin for job listing and recruitment functionality. An unauthenticated PHP object injection vulnerability allows attackers to manipulate server-side data processing and execute arbitrary code without requiring a login or special access, potentially leading to complete site compromise and data theft.
Technical details
The vulnerability is a PHP object injection flaw in the JobSearch WordPress plugin affecting versions 3.2.0 and earlier. It allows unauthenticated attackers to inject and deserialize malicious PHP objects, which can be leveraged to achieve remote code execution on the server. The attack requires only network access to the vulnerable plugin endpoint—no authentication or user interaction is needed. A successful exploit grants an attacker full control over the WordPress installation and underlying server. As of the advisory date, no official patch was available; mitigation via a WAF rule or plugin update to a version beyond 3.2.0 is recommended.
Affected products
- EyeCix Technologies JobSearch 3.2.0 and earlier
Timeline
- 2026-09-03: disclosed: Published by Patchstack
- 2026-01-14: other: Reported by Phat RiO