Impact
The Workeera WordPress plugin allows candidates to submit arbitrary profile data without restriction or validation of the file type that may be saved to a publicly accessible directory. Because these submissions are not properly checked, a user with a low‑privilege role such as subscriber can upload any file, including executable code, that can then be executed by the web server, resulting in full remote code execution.
Affected Systems
Any WordPress site that has installed the Workeera plugin prior to version 1.0.6 is affected. The plugin is distributed by an unknown vendor and is used to manage job board candidate profiles. Subscribers or any logged‑in user with the ability to create or edit a candidate profile can trigger the flaw.
Risk and Exploitability
The vulnerability enables an attacker to run arbitrary code on the affected web server with the permissions of the user role that uploads the file—subscribers have very low privileges but can still upload the file. The likely attack vector is through mass assignment of candidate profile data, allowing a subscriber to upload files. The EPSS score is < 1%, and the CVSS score is 8.8. The flaw is not listed in the CISA KEV catalog. However, the combination of unrestricted file upload and remote code execution presents a high severity risk, as exploitation requires only the ability to create or edit a candidate profile, a common task for many users on a job board site.
OpenCVE Enrichment