CRITICAL
9.6 CVE-2026-77016 Published 27 Aug 2026
WordPress Workeera Plugin Arbitrary File Deletion
Worried this affects one of your servers?
The Workeera WordPress plugin, versions prior to 1.0.6, contains a critical security vulnerability.
This plugin does not restrict or validate user input when updating a user's candidate profile, allowing users with the lowest 'subscriber' role to delete arbitrary files on the server.
Impact: Successful exploitation of this vulnerability could result in unauthorized file deletion, leading to data loss or server compromise.
Reference: CVE-2026-77016 on NVD
← Back to Security News