
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24978 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the NooTheme Jobica Core WordPress plugin, affecting all versions up to and including 1.4.1. The vulnerability was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on December 14, 2025, and published by Patchstack on March 16, 2026. It carries a CVSS v3.1 base score of 8.8 (High), requiring only low-level privileges and no user interaction for network-based exploitation (Patchstack).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The plugin fails to safely handle deserialization of user-supplied data, allowing an authenticated attacker with subscriber-level privileges to inject malicious PHP objects. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress environment, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service (Patchstack).
Successful exploitation can result in full compromise of confidentiality, integrity, and availability of the affected WordPress site. Depending on the availability of a POP chain in the target environment, an attacker could execute arbitrary code, perform SQL injection, traverse the file system, or cause a denial of service. Given that the attacker only needs subscriber-level access, the barrier to exploitation is low, and mass-exploit campaigns targeting thousands of WordPress sites are a realistic threat (Patchstack).
There is no public proof-of-concept exploit or evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. Exploitation requires at least subscriber-level authentication and a viable POP chain in the target environment, which somewhat limits opportunistic attacks. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
unserialize() calls.bash, curl, wget) that may indicate successful code execution via a POP chain.The vendor has released version 1.4.2 of the Jobica Core plugin, which resolves this vulnerability. Site administrators should update to version 1.4.2 or later immediately. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for its users to block exploitation attempts until the plugin is updated. Additionally, restricting user registration or subscriber-level access on affected sites can reduce the attack surface (Patchstack).
The vulnerability was covered in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the period of March 16–22, 2026, highlighting it among notable plugin vulnerabilities. Patchstack, which coordinated disclosure, classified it as high priority and noted its potential for use in mass-exploit campaigns targeting WordPress sites (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."