Impact
The Workeera WordPress plugin, prior to version 1.0.6, fails to enforce read/write restrictions on a subscriber’s candidate profile. It accepts any submitted value for the profile fields and deletes files based on the stored path without validation. A subscriber can therefore craft a profile update that points to any file on the server and trigger its deletion. This arbitrary file deletion can remove critical configuration files, web assets, or database backups, leading to data loss or site downtime.
Affected Systems
WordPress sites running the Workeera job board plugin before the 1.0.6 release are affected. Any installation with an older version (e.g., 1.0.5 or earlier) is vulnerable if subscriber accounts exist on the site.
Risk and Exploitability
The vulnerability is exploitable by any user who has the subscriber role on the affected WordPress installation. No remote code execution or external trigger is required; the attacker only needs the ability to update their own candidate profile. The risk is limited by the distribution of subscriber accounts, but based on the description, it is inferred that a compromised or malicious subscriber can delete arbitrary files, potentially disrupting the site or compromising data. CVSS score 9.6 and EPSS score < 1% are available, but it is not listed in the CISA KEV catalog, nevertheless the impact of arbitrary file deletion warrants immediate attention.
OpenCVE Enrichment