CVE-2026-84834: WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
Affected Software
1 affected component
WordPress JobSearch<=3.2.0
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or any existing privileges to attempt exploitation.
2
Which installations are affected?
WordPress sites using the JobSearch plugin at version 3.2.0 or earlier are affected according to the available information.
3
Does exploitation require user interaction or a complex attack setup?
The supplied severity vector indicates network-based exploitation with low attack complexity and no user interaction required.