sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical1
High2
Medium0
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-08-28

Workeera - Improper Input Validation (CVE-2026-77016)

The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server.

PLUGIN Workeera

CVE-2026-77016

CRITICAL CVSS 9.6 2026-08-27
Threat Entry Updated 2026-08-28

Workeera - Remote Code Execution (CVE-2026-77018)

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution.

PLUGIN Workeera

CVE-2026-77018

HIGH CVSS 8.8 2026-08-27
Threat Entry Updated 2026-08-28

Workeera - Security Vulnerability (CVE-2026-77017)

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.

PLUGIN Workeera

CVE-2026-77017

HIGH CVSS 7.7 2026-08-27