top of page
perceptive_background_267k.jpg

The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain th…

Published:

27 August 2026 at 00:00:00

Alert date:

27 August 2026 at 20:17:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

The Workeera WordPress plugin before version 1.0.6 contains a critical vulnerability allowing low-privileged users (subscriber role or higher) to delete arbitrary files on the server. The plugin fails to restrict which values can be written to a user's candidate profile and does not validate or sanitize the stored file path before deletion. This lack of input validation and access control enables attackers to exploit the file deletion functionality maliciously. The vulnerability could lead to significant damage including deletion of critical system files, configuration files, or other sensitive data. Users are advised to update to version 1.0.6 or later to remediate the issue.

Technical details

Mitigation steps:

Affected products:

Workeera WordPress Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page