Career Section WordPress Plugin Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability allowing arbitrary file upload has been identified in the Career Section plugin for WordPress, affecting all versions through 1.7. The issue arises from inadequate file type validation in the CV upload handler, enabling unauthenticated attackers to upload potentially executable files, which could lead to remote code execution.

Impact

Exploitation of this vulnerability allows for arbitrary file upload, with the potential for uploaded files to be executed on the server, leading to remote code execution.

Reproduction

To reproduce this vulnerability, upload a file through the CV upload feature of the Career Section plugin version 1.7 or earlier. The absence of proper file type validation allows the upload of executable files.

Remediation

Users are advised to update the Career Section plugin to version 1.8 or later.

Added: May 14, 2026, 7:28 AM
Updated: May 14, 2026, 7:28 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.4
remediation
0.0
relevance
8.3
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.