CRITICAL 9.6 CVE-2026-77016 Published 27 Aug 2026

WordPress Workeera Plugin Arbitrary File Deletion

Worried this affects one of your servers?

The Workeera WordPress plugin, versions prior to 1.0.6, contains a critical security vulnerability.

This plugin does not restrict or validate user input when updating a user's candidate profile, allowing users with the lowest 'subscriber' role to delete arbitrary files on the server.

Impact: Successful exploitation of this vulnerability could result in unauthorized file deletion, leading to data loss or server compromise.

Reference: CVE-2026-77016 on NVD

← Back to Security News