Sceawere
Vulnerability Detail
CVE-2026-39759UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Workreap Core Arbitrary File Upload
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 16h ago
- Vendor
- AmentoTech
- Product
- Workreap Core
- Attack Type
- CWE-434 Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-10-06T09:17:47.853Z",
"pubdate": "2026-10-06T09:17:47.853Z",
"executiveSummary": "The Workreap Core plugin for WordPress, in versions 3.4.5 and below, contains an arbitrary file upload vulnerability. This flaw exists within the Employer and Sales Representative profile management modules, allowing authenticated users with low-level privileges to bypass file type validation restrictions.\nThe vulnerability type is categorized as an Unrestricted Upload of File with Dangerous Type (CWE-434). An attacker can leverage this weakness to upload arbitrary files, including malicious PHP scripts, directly to the web server's filesystem.\nSuccessful exploitation grants the attacker the ability to achieve Remote Code Execution (RCE) by accessing the uploaded file via a direct HTTP request. This could result in a full site compromise, including unauthorized data access, modification of site content, potential lateral movement within the hosting environment, or the deployment of backdoors for persistent access.\nThe attack vector is network-based and requires the attacker to hold at least a registered user account with Employer or Sales Representative privileges. There are no complex social engineering requirements; the attacker simply needs to interact with the vulnerable file upload functionality provided by the plugin.",
"technicalDetails": "The vulnerability resides in the Workreap Core plugin's handling of profile avatar and document uploads. Specifically, the application fails to perform adequate server-side validation of file extensions and MIME types before moving user-supplied files into the web-accessible uploads directory.\nThe root cause is an improper implementation of security controls in the file processing logic, which relies on client-side checks or weak server-side filters that can be easily bypassed by intercepting and modifying the HTTP POST request. By manipulating the 'Content-Type' header or renaming a PHP executable file with a double extension (e.g., shell.php.jpg), an attacker can trick the server-side validator into accepting a malicious payload.\nAttack Flow: 1. The attacker authenticates as a legitimate Employer or Sales Representative. 2. The attacker navigates to the profile settings or document upload interface provided by Workreap Core. 3. Using an interception proxy (such as Burp Suite), the attacker initiates a multipart/form-data upload, substituting the legitimate profile image or document with a web shell script. 4. If the server-side logic fails to inspect the file content or strictly validate the final extension, the server writes the malicious script to the /wp-content/uploads/ directory. 5. Once the file is persisted, the attacker identifies the URI of the uploaded script. 6. The attacker sends a direct GET request to the uploaded file URI, causing the server to execute the embedded code within the context of the web server process.\nThe vulnerable component is the file upload handler within the Workreap Core plugin. Because the plugin processes these uploads without utilizing a non-executable directory or renaming files to non-parseable formats, the web server (Apache/Nginx/IIS) interprets the uploaded code upon direct access. This leads to arbitrary command execution, enabling the attacker to leverage the server's environment to execute shell commands, read sensitive database credentials from 'wp-config.php', or exfiltrate the contents of the WordPress database.\nThe vulnerability is present in versions up to 3.4.5. The impact is critical as it allows for complete system compromise if the web server process runs with sufficient privileges or if the underlying OS is susceptible to further privilege escalation."
}