Unauthenticated SQL Injection in JobSearch Plugin by WordPress
CVE-2026-54186

9.3CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2026-54186?

The JobSearch plugin for WordPress is susceptible to an unauthenticated SQL Injection vulnerability that impacts versions up to 3.2.9. This flaw allows attackers to inject malicious SQL code, potentially leading to unauthorized access to sensitive database information. Administrators of affected sites are strongly advised to update to the latest versions and implement security best practices to mitigate risks associated with SQL injections.

Affected Version(s)

JobSearch <= 3.2.9

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh | Patchstack Bug Bounty Program
.