CVE-2026-77017
N/A
N/A
Summary
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Workeera | 0 < 1.0.6 | affected |
Weaknesses
- CWE-200 Information Exposure
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.