← back

CVE-2026-6271

CRITICAL · 9.8
hype MIXED · 45 hack

Fresh disclosure, no PoC/KEV/exploitation signals yet; chatter is advisory amplification.

What: Career Section WordPress plugin vulnerable to unauthenticated arbitrary file upload leading to remote code execution in all versions ≤1.7 (CVSS 9.8 CRITICAL).

Why it matters: Published today with CVSS 9.8 and no patch available. Affects unauthenticated attackers uploading executable files via CV handler. Not yet KEV-listed, but social chatter is immediate and widespread. No confirmed PoC or in-the-wild exploitation reported yet.

Where it's seen: Security researchers and automated CVE feeds posting advisory summaries within hours of NVD publication. One vendor security account flagging "no patch yet." Mostly retweets of the same disclosure across Bluesky and Twitter.

RISK: CRITICAL — Unauthenticated RCE in popular WordPress plugin; no patch available; high CVSS.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 5/14/2026, 10:34:36 AM

Description

The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Weaknesses