CVE-2026-100511: WordPress VK Google Job Posting Manager plugin <= 1.3.1 - PHP Object Injection vulnerability
Published Oct 5, 2026
·Updated
Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
Affected Software
1 affected component
Vektor Inc. VK Google Job Posting Manager<=1.3.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress VK Google Job Posting Managerto a version that resolves this vulnerability.Fixed in 1.3.2
Event History
Oct 5, 2026
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is network-accessible and requires low privileges. No user interaction is required.
2
What impact could successful exploitation have?
Successful exploitation could affect confidentiality, integrity, and availability at a high level.
3
Which versions are affected?
VK Google Job Posting Manager versions through 1.3.1 are affected. The available data does not identify a fixed version.