LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-6271

Published
CVSS9.8
Severitycritical
WeaknessCWE-434
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-6271

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-6271.