Description
Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08.
Published: 2026-07-13
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the WorkScout-Core plugin allows a remote attacker to perform cross‑site request forgery that results in authentication bypass. The flaw enables the attacker to execute privileged actions without needing valid user credentials, directly compromising the confidentiality and integrity of the WordPress site.

Affected Systems

The affected product is the WordPress plugin WorkScout-Core by purethemes. All releases from the earliest available version up to and including 1.7.08 are affected. No other versions are listed as impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity weakness. The EPSS score of less than 1% shows a currently low exploitation probability, yet the vulnerability is still noteworthy. It is not listed in the CISA KEV catalog. The likely attack vector is a CSRF attack that an attacker can trigger through a malicious link or embedded content accessed by an authenticated user, granting the attacker unauthorized access.

Generated by OpenCVE AI on August 1, 2026 at 10:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest available version of WorkScout‑Core to remove the CSRF flaw.
  • If an upgrade cannot be performed immediately, deactivate or delete the plugin from the WordPress installation until the patch is applied.
  • Review site user roles and apply principle‑of‑least‑privilege controls to minimize potential damage if an authentication bypass were to occur.

Generated by OpenCVE AI on August 1, 2026 at 10:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Purethemes
Purethemes workscout Core
Wordpress
Wordpress wordpress
Vendors & Products Purethemes
Purethemes workscout Core
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08.
Title WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF) to Broken Authentication vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Purethemes Workscout Core
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:49.745Z

Reserved: 2026-06-25T08:04:53.459Z

Link: CVE-2026-57786

cve-icon Vulnrichment

Updated: 2026-07-13T16:01:57.334Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)