PHP Remote File Inclusion Vulnerability in JobSearch by eyecix
CVE-2025-52806

7.5HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
14 August 2025

What is CVE-2025-52806?

The JobSearch plugin by eyecix contains a vulnerability due to improper control of filename handling in its PHP include/require statements. This allows attackers to potentially exploit local file inclusion, enabling unauthorized access to sensitive files on the server. Affected versions range from an unspecified release to 2.9.0. It is crucial for users of this plugin to implement necessary updates and security measures to protect against this risk.

Affected Version(s)

JobSearch <= 2.9.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.