WordPress Plugin Vulnerabilities

Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload via Candidate Profile Mass Assignment

Description

The plugin does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-08-25 (about 23 days ago)
Added
2026-08-25 (about 22 days ago)
Last Updated
2026-08-25 (about 22 days ago)

Other