CyberRota Analysis
AI-GeneratedThe Workeera WordPress plugin prior to version 1.0.6 is vulnerable due to insufficient restrictions on profile value submissions and file storage locations, enabling users with minimal permissions, such as subscribers, to access arbitrary files on the server. This can lead to exposure of sensitive information, including configuration files and authentication secrets. WordPress site administrators and security teams should prioritize this vulnerability to mitigate potential data breaches.
Original NVD Description
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.