Sploitus

CVE-2026-6271

2 known exploits for CVE-2026-6271

The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

Affected products
Career Section
CVSS 3.1
9.8 CRITICAL
EPSS
0.7% (49th percentile)
Weakness
CWE-434
NVD status
Deferred
Published
2026-05-14
CVE-2026-6271 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-6271

Proof-of-concept code and exploit modules indexed by Sploitus