CVE-2025-62025

9.8

eyecix · JobSearch WP Job Board

A deserialization of untrusted data vulnerability in the JobSearch WP Job Board plugin allows unauthenticated attackers to execute arbitrary code.

Executive summary

A critical deserialization vulnerability in the JobSearch WP Job Board plugin allows unauthenticated remote attackers to achieve full system compromise.

Vulnerability

This vulnerability involves the insecure deserialization of untrusted data, which can be leveraged by an unauthenticated attacker to inject malicious objects and achieve remote code execution.

Business impact

Successful exploitation of this flaw grants an attacker full control over the affected WordPress installation, leading to complete data compromise, site defacement, or the potential for lateral movement within the hosting environment. While the vendor-provided score is 8.1, the CVSS base score of 9.8 reflects the potential for unauthenticated, remote, and total impact, necessitating immediate prioritization.

Remediation

Immediate Action: Update the JobSearch WP Job Board plugin to version 3.0.8 or later immediately.

Proactive Monitoring: Monitor server access logs for unusual POST requests targeting plugin-specific endpoints or patterns indicative of PHP object injection.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common PHP object injection payloads and unauthorized access to plugin administrative functions.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity and the potential for unauthenticated remote code execution, organizations must treat this as a high-priority update. Ensure all instances of the JobSearch plugin are patched to version 3.0.8 or higher immediately to eliminate the risk of unauthorized system access.