CRITICAL SeverityCVSS 3.19.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-6271
Last updated May 14, 2026 · Published May 14, 2026
Description
The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
Affected products
1 listed- shahinurislam:Career Section
Mappings
CWE
CWE-434
CAPEC
None listed.
Related
Guides
Training
CVE® content © MITRE Corporation. Licensed under the CVE Terms of Use. Terms
