The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Workeera WordPress plugin before version 1.0.6 contains a critical arbitrary file deletion vulnerability stemming from insufficient input validation and path traversal protection. By exploiting the candidate profile update functionality, attackers with subscriber-level privileges—the lowest authenticated role in WordPress—can manipulate file path parameters to delete any file accessible to the web server process. This vulnerability is particularly dangerous because it requires minimal access requirements and can lead to complete site compromise through deletion of critical WordPress configuration files, database backups, or security plugins. Any WordPress installation using this plugin before 1.0.6 is exposed, affecting potentially thousands of websites that rely on the Workeera recruitment functionality.
While this CVE does not map to specific MITRE ATT&CK techniques in public databases, Casky's extended reasoning capabilities would detect the attack patterns associated with Defense Evasion (T1070 - Indicator Removal) and Impact (T1531 - Account Access Removal, T1485 - Data Destruction) tactics. Practitioners using Casky would observe findings flagging suspicious profile update requests containing path traversal sequences (../, encoded variants), unexpected file deletion operations post-authentication, and logs showing subscriber accounts performing file system operations beyond normal profile scope. The platform's 754 mapped security skills would enable detection of anomalous behavior patterns: low-privileged users triggering deletion operations, unvalidated input reaching file system operations, and POST requests to profile endpoints containing file path parameters—all signature indicators of this exploitation chain.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-77016. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation