Sceawere

Vulnerability Detail

CVE-2026-39752UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Jobs for WordPress Arbitrary Deletion

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
16h ago
Vendor
BlueGlass Interactive AG
Product
Jobs for WordPress
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-10-06T09:17:46.790Z",
  "pubdate": "2026-10-06T09:17:46.790Z",
  "executiveSummary": "The Jobs for WordPress plugin, specifically in versions 2.8.2 and below, contains a critical security vulnerability categorized as an Arbitrary File Deletion flaw. This vulnerability stems from improper input validation within the plugin's file handling mechanisms. An attacker with a Contributor-level account or higher can leverage this vulnerability to delete sensitive files on the server hosting the WordPress instance.\nThe impact of this vulnerability is severe, as it facilitates potential Denial of Service (DoS) by removing essential WordPress core files, configuration files like wp-config.php, or plugin-related data. By successfully executing this attack, a malicious actor can compromise the integrity and availability of the target web application. Exploitation requires authenticated access at the Contributor role level, meaning the attacker must be a registered user on the WordPress site. Due to the destructive nature of the vulnerability, it presents a significant risk to site stability and data continuity.",
  "technicalDetails": "The vulnerability originates from a lack of server-side sanitization or validation on user-supplied input paths used in file management operations within the Jobs for WordPress plugin. In affected versions (<= 2.8.2), the application fails to enforce restrictive access controls or directory traversal protections when handling requests initiated by authenticated users with a Contributor role.\nThe attack flow typically begins with an authenticated Contributor crafting a malicious HTTP request that targets the vulnerable function responsible for deleting plugin-associated files. Because the application does not properly restrict the file path input, an attacker can supply absolute paths or use directory traversal sequences (e.g., ../) to reference files outside the intended directory scope.\nOnce the request is submitted, the server-side code processes the path and executes a file deletion command using the unsanitized input. Since the web server process typically operates with the permissions of the web user, the plugin is capable of deleting any file that the web user has write or delete permissions for, which often includes the entire WordPress installation directory.\nStep-by-step exploitation involves: 1) The attacker authenticates to the WordPress instance as a Contributor. 2) The attacker intercepts or crafts a request to the vulnerable endpoint associated with the plugin's file handling functionality. 3) The attacker injects a target file path (e.g., /var/www/html/wp-config.php) into the susceptible parameter. 4) The plugin executes the deletion function, resulting in the removal of the specified file. 5) The deletion of critical files leads to immediate site instability or complete application failure.\nThis vulnerability highlights a critical failure in the Principle of Least Privilege and Input Validation security controls. The absence of a whitelist-based approach to file deletion paths allows an attacker to manipulate the file system, leading to destructive consequences. The impact is persistent and often necessitates manual recovery from backups, as the removed files are non-recoverable via the application interface."
}
CVE-2026-39752: Jobs for WordPress Arbitrary Deletion (HIGH Severity, CVSS: 7.7) | Sceawere