Sceawere
Vulnerability Detail
CVE-2026-39752UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Jobs for WordPress Arbitrary Deletion
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.7
- Creation Date
- 16h ago
- Vendor
- BlueGlass Interactive AG
- Product
- Jobs for WordPress
- Attack Type
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.7",
"pubDate": "2026-10-06T09:17:46.790Z",
"pubdate": "2026-10-06T09:17:46.790Z",
"executiveSummary": "The Jobs for WordPress plugin, specifically in versions 2.8.2 and below, contains a critical security vulnerability categorized as an Arbitrary File Deletion flaw. This vulnerability stems from improper input validation within the plugin's file handling mechanisms. An attacker with a Contributor-level account or higher can leverage this vulnerability to delete sensitive files on the server hosting the WordPress instance.\nThe impact of this vulnerability is severe, as it facilitates potential Denial of Service (DoS) by removing essential WordPress core files, configuration files like wp-config.php, or plugin-related data. By successfully executing this attack, a malicious actor can compromise the integrity and availability of the target web application. Exploitation requires authenticated access at the Contributor role level, meaning the attacker must be a registered user on the WordPress site. Due to the destructive nature of the vulnerability, it presents a significant risk to site stability and data continuity.",
"technicalDetails": "The vulnerability originates from a lack of server-side sanitization or validation on user-supplied input paths used in file management operations within the Jobs for WordPress plugin. In affected versions (<= 2.8.2), the application fails to enforce restrictive access controls or directory traversal protections when handling requests initiated by authenticated users with a Contributor role.\nThe attack flow typically begins with an authenticated Contributor crafting a malicious HTTP request that targets the vulnerable function responsible for deleting plugin-associated files. Because the application does not properly restrict the file path input, an attacker can supply absolute paths or use directory traversal sequences (e.g., ../) to reference files outside the intended directory scope.\nOnce the request is submitted, the server-side code processes the path and executes a file deletion command using the unsanitized input. Since the web server process typically operates with the permissions of the web user, the plugin is capable of deleting any file that the web user has write or delete permissions for, which often includes the entire WordPress installation directory.\nStep-by-step exploitation involves: 1) The attacker authenticates to the WordPress instance as a Contributor. 2) The attacker intercepts or crafts a request to the vulnerable endpoint associated with the plugin's file handling functionality. 3) The attacker injects a target file path (e.g., /var/www/html/wp-config.php) into the susceptible parameter. 4) The plugin executes the deletion function, resulting in the removal of the specified file. 5) The deletion of critical files leads to immediate site instability or complete application failure.\nThis vulnerability highlights a critical failure in the Principle of Least Privilege and Input Validation security controls. The absence of a whitelist-based approach to file deletion paths allows an attacker to manipulate the file system, leading to destructive consequences. The impact is persistent and often necessitates manual recovery from backups, as the removed files are non-recoverable via the application interface."
}