Product
critical
threat
CVE-2026-6271: WordPress Career Section Plugin Arbitrary File Upload Vulnerability
2 rules 1 CVEThe Career Section plugin for WordPress is vulnerable to arbitrary file upload in versions up to 1.7 due to missing file type validation in the CV upload handler, potentially leading to remote code execution.
Career Section plugin
arbitrary file upload
remote code execution
wordpress plugin
2r
1c
high
advisory
Career Section WordPress Plugin CSRF Vulnerability Leading to Arbitrary File Deletion
2 rules 1 TTP 1 CVEThe Career Section WordPress plugin, versions 1.6 and earlier, is vulnerable to cross-site request forgery (CSRF), allowing unauthenticated attackers to delete arbitrary files on the server by tricking a site administrator.
Career Section Plugin
wordpress
csrf
file-deletion
cve-2025-14868
2r
1t
1c