WordPress Plugin Vulnerabilities

Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion via Candidate Profile Mass Assignment

Description

The plugin does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server.

Proof of Concept

Affects Plugins

References

Classification

Type
FILE DELETION
CWE

Miscellaneous

Original Researcher
Artus KG and Shhriyash
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-25 (about 3 days ago)
Added
2026-08-25 (about 2 days ago)
Last Updated
2026-08-25 (about 2 days ago)

Other