Workeera – AI Job Board with Applicant Tracking System (ATS) < 1.0.6 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Workeera – AI Job Board with Applicant Tracking System (ATS) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to 1.0.6. This is due to missing file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on...
- CVSS:
- 8.8
(Wordfence)
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Aug 27, 2026
CVE-2026-77018 on NVD →
Workeera – AI Job Board with Applicant Tracking System (ATS) < 1.0.6 - Authenticated (Subscriber+) Arbitrary File Read
medium
The Workeera – AI Job Board with Applicant Tracking System (ATS) plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to 1.0.6. This is due to insufficient validation of a user supplied path. This makes it possible for authenticated attackers, with subscriber-level access and above, to read arbi...
- CVSS:
- 6.5
(Wordfence)
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Aug 27, 2026
CVE-2026-77017 on NVD →
Workeera – AI Job Board with Applicant Tracking System (ATS) < 1.0.6 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The Workeera – AI Job Board with Applicant Tracking System (ATS) plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient file path validation in all versions up to 1.0.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on th...
- CVSS:
- 8.1
(Wordfence)
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Aug 25, 2026
CVE-2026-77016 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database