VYPR
Unrated severityNVD Advisory· Published Jun 16, 2026

WordPress JobSearch plugin <= 3.2.7 - Broken Access Control vulnerability

CVE-2026-49057

Description

Unauthenticated broken access control in JobSearch plugin <=3.2.7 allows attackers to execute privileged actions, posing a high risk of mass exploitation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated broken access control in JobSearch plugin <=3.2.7 allows attackers to execute privileged actions, posing a high risk of mass exploitation.

Vulnerability

The JobSearch plugin for WordPress versions up to and including 3.2.7 contains a broken access control vulnerability. This issue arises from missing authorization or nonce checks in a function, allowing unauthenticated users to perform actions that should require higher privileges. The vulnerability is classified as unauthenticated broken access control [1].

Exploitation

An attacker can exploit this vulnerability without any authentication by sending specially crafted HTTP requests to the vulnerable endpoint. No user interaction or special network position is required. The vulnerability is considered highly dangerous and is expected to be used in mass-exploit campaigns targeting thousands of websites [1].

Impact

Successful exploitation enables an unauthenticated attacker to execute higher privileged actions, potentially leading to full site compromise, unauthorized data access, or other malicious operations. The exact impact depends on the specific function affected, but the lack of access control can result in significant security breaches [1].

Mitigation

The vulnerability is fixed in version 3.2.8 of the JobSearch plugin. Users are strongly advised to update immediately. For those unable to update, Patchstack has issued a mitigation rule to block attacks until the update is applied. Given the expected mass exploitation, prompt action is critical [1].

AI Insight generated on Jun 17, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

2