External risk intelligence

Workeera WordPress Plugin Arbitrary File Deletion Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-77016

The vulnerability exists in a WordPress plugin. WordPress sites are commonly deployed as public-facing web applications accessible via the internet. While the action requires subscriber-level authentication, the plugin's role as part of a public-facing web service makes the vulnerable component inherently reachable from the internet in common deployment scenarios.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the Workeera WordPress plugin that could allow users with low-level access to delete arbitrary files on the server. This could potentially impact the integrity and availability of the affected system.

  • Allows low-access users to delete server files.
  • Matters due to common WordPress deployment reachability.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by leveraging a low-privileged user account, such as a subscriber, to trigger the insecure file deletion functionality within the Workeera WordPress plugin. This misconfiguration allows the attacker to delete arbitrary files from the server, potentially leading to significant disruption or data loss.

  • Requires low-privileged user access.
  • Deletes arbitrary files on the server.
  • Can cause system disruption.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged user, such as a subscriber, could delete arbitrary files on the server when they have access to the Workeera WordPress plugin. This could impact the integrity and availability of the server.

  • Server files and system integrity.
  • Authenticated user can delete files.
  • Server availability and data integrity loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Workeera WordPress plugin's arbitrary file deletion vulnerability requires immediate attention from teams managing WordPress deployments. The first practical step is to identify all instances of this plugin, confirm their exposure to the internet and business criticality, and then locate the accountable application or site owner. Remediation planning should be risk-based, prioritizing the most exposed or critical systems.

  • Application owners should manage this issue.
  • Verify plugin presence and reachability first.
  • Plan targeted remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Workeera WordPress plugin?

Workeera is a plugin designed for the WordPress content management system, typically used to manage recruitment or candidate profile workflows. It enables site administrators to handle job-related data directly within their WordPress dashboard, providing a structured way for users to submit or update their professional information.

What does CVE-2026-77016 mean?

This CVE identifies a security weakness known as CWE-73, or External Control of File Name or Path. It means the software does not properly check or limit the file paths it processes. Because of this flaw, the plugin can be tricked into deleting files on the server it does not have legitimate permission to modify.

How can an attacker trigger this vulnerability?

An attacker needs an active account on the WordPress site with at least subscriber-level permissions to interact with the plugin's profile features. It is important to note that this is not a blind exploit; the attacker must be logged in to reach the specific functionality that fails to validate the file paths before deletion.

Why should I care about this vulnerability?

According to Halo Surface Signal, this plugin is often used on public-facing websites, making the vulnerable component reachable over the internet. If your WordPress site allows user registration, an attacker could potentially abuse a low-level account to delete critical system files, impacting your site's overall availability.

Do I need to update my software?

Yes, start by identifying if you have Workeera installed in your WordPress environment. If the version is older than 1.0.6, your installation is likely affected. Coordinate with your site owners to confirm the plugin's presence, assess the criticality of the site, and prioritize updating the plugin to a secured version to prevent unauthorized file removal.

References