SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77018

HIGH · CVSS 8.8 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Workeera WordPress plugin prior to version 1.0.6 is vulnerable due to inadequate restrictions on profile value submissions and a lack of validation for uploaded file types, enabling users with minimal permissions to upload arbitrary files. This flaw could lead to remote code execution, posing a significant risk to the integrity and security of the affected WordPress installations. WordPress site administrators and security teams should prioritize updating this plugin to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77018
Severity
HIGH
CVSS
8.8
EPSS
0.41%
WordPress

Original NVD Description

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution.