CVE-2026-77016: Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion via Candidate Profile Mass Assignment
The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Workeera Remote Tech Job Boardto a version that resolves this vulnerability.Fixed in 1.0.6 - Compensating control
Since Workeera Remote Tech Job Board versions prior to 1.0.6 allow subscriber+ users to delete arbitrary files via candidate profile mass assignment, restrict access to any functionality that allows role-based candidate profile editing/deletion to only users who truly need it until the plugin is upgraded to 1.0.6 or later.
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user with at least the Subscriber role can exploit it. The affected user must be able to modify their own candidate profile.
What does an attacker need to do to delete files?
The attacker needs to write a file path into their candidate profile through the unrestricted profile fields. The plugin then deletes the stored path without validating or containing it.
Are unauthenticated visitors affected?
The available information describes exploitation by authenticated users with a role as low as Subscriber. It does not indicate that unauthenticated visitors can exploit the issue.
What version should be remediated?
Versions before 1.0.6 are affected. Upgrade to version 1.0.6 or later.