PatchSiren cyber security CVE debrief
CVE-2026-22340 Jobster Marketplace CVE debrief
A critical vulnerability was discovered in the WPJobster WordPress theme, versions up to 6.3.5. This vulnerability allows unauthenticated attackers to inject malicious SQL code, potentially leading to data breaches and unauthorized access. With a CVSS score of 9.3, this issue is considered critical and requires immediate attention. WPJobster users must take swift action to protect their installations. The vulnerability was made public on June 17, 2026.
- Vendor
- Jobster Marketplace
- Product
- WPJobster
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
WPJobster users, WordPress administrators, cybersecurity professionals, and organizations relying on WPJobster for job management should be aware of this vulnerability and take necessary precautions to secure their installations.
Technical summary
The vulnerability is an unauthenticated SQL injection issue in the WPJobster WordPress theme, affecting versions up to 6.3.5. This allows attackers to execute arbitrary SQL code without requiring authentication, potentially leading to data extraction, modification, or deletion. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L, indicating a high impact on confidentiality and a moderate attack complexity.
Defensive priority
critical
Recommended defensive actions
- Update WPJobster to the latest version available, which should include a patch for this vulnerability.
- Implement a Web Application Firewall (WAF) to detect and block suspicious SQL injection attempts.
- Regularly monitor WPJobster installations for signs of exploitation.
- Restrict access to sensitive areas of the WPJobster application.
- Perform regular security audits and vulnerability assessments.
- Consider using security plugins or services that offer SQL injection protection.
- Keep all WordPress and plugin installations up-to-date.
Evidence notes
The information provided is based on data from official sources, including the CVE record and NVD details. The vulnerability was reported by Patchstack and is tracked under CVE-2026-22340. The CVSS score and vector were obtained from the NVD database.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-22340 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-22340
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-22340 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-22340
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.