A critical unauthenticated PHP Object Injection vulnerability has been identified in the JobSearch WordPress plugin affecting versions 3.2.0 and earlier. The vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to remote code execution or other severe impacts depending on available POP chains. The flaw is documented under CVE-2026-84834 and has been reported via both the NVD and Patchstack databases. No authentication is required to exploit this vulnerability, significantly raising its risk profile. WordPress site administrators using the JobSearch plugin are advised to update to a patched version immediately. The vulnerability was disclosed through Patchstack's coordinated vulnerability disclosure program.