WordPress Plugin Vulnerabilities
Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload via Candidate Profile Mass Assignment
Description
The plugin does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-25 (about 23 days ago)
Added
2026-08-25 (about 22 days ago)
Last Updated
2026-08-25 (about 22 days ago)