JobSearch WP Job Board Plugin Unauthenticated PHP Object Injection

Release Date: 3rd September 2026 (Added 8th September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and website/HR teams that operate a WordPress site using the JobSearch (eyecix) job board plugin. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-84834 is a critical, unauthenticated PHP Object Injection vulnerability in JobSearch, a commercial WordPress job-board plugin by eyecix sold on the Envato CodeCanyon marketplace, with over 2,640 recorded sales and a 4.5-star rating across 260 reviews, used by organizations to publish job listings and manage employer/candidate applications on their own WordPress sites. The flaw allows an attacker to submit specially-crafted serialized PHP data that the plugin deserializes without validating its origin or type. If the WordPress installation (core, another plugin, or a theme) contains a suitable “gadget chain”.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-84834
  2. https://codecanyon.net/item/jobsearch-wp-job-board-wordpress-plugin/21066856