CVE-2026-77018
N/A
N/A
Summary
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Workeera | 0 < 1.0.6 | affected |
Weaknesses
- CWE-434 Unrestricted Upload of File with Dangerous Type
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.