Output validation vulnerability in WP Job Manager 1.31.3

The WP Job Manager plugin for WordPress is vulnerable to a type of cyber attack in versions up to and including 1.31.2. This type of attack, called PHP Object Injection, is done by deserializing user-controlled input which allows a malicious actor to inject a PHP Object. As of now, there is no known way for an attacker to use this vulnerability to do anything destructive. However, if the target system has an additional plugin or theme installed, the attacker may be able to delete data, retrieve sensitive information, or execute code.

Detected in:

2.3.0 – 2024-04-26 fixed vulnerable versions:
WP Job Manager fixed vulnerable versions: >= * < 1.31.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.