plugin

Career Section Vulnerabilities

4 known security issues reported for the Career Section WordPress plugin. Most recent disclosed May 14, 2026.

1 critical 1 high

Running Career Section on your site? Check whether your installed version is affected.

Scan your site free

Career Section [career-section] < 1.8

unknown

[en] The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execu...

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
May 14, 2026

CVE-2026-6271 on NVD →

Career Section <= 1.7 - Unauthenticated Arbitrary File Upload

critical

The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution...

CVSS:
9.8
Affected:
up to 1.7
Fixed in:
1.8
Disclosed:
May 13, 2026

CVE-2026-6271 on NVD →

Career Section [career-section] < 1.7

unknown

[en] The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versions up to, and including, 1.6. This is due to missing nonce validation and insufficient file path validation on the delete action in the 'appform_options_page_html'...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Apr 16, 2026

CVE-2025-14868 on NVD →

Career Section <= 1.6 - Cross-Site Request Forgery to Arbitrary File Deletion

high

The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versions up to, and including, 1.6. This is due to missing nonce validation and insufficient file path validation on the delete action in the 'appform_options_page_html' funct...

CVSS:
8.8
Affected:
up to 1.6
Fixed in:
1.7
Disclosed:
Apr 15, 2026

CVE-2025-14868 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database