Junglewise Threat Intelligence

CVE-2026-52716: purethemes WorkScout-Core arbitrary file deletion via path traversal

CVE-2026-52716 · Severity: medium · CVSS 6.5 · Published 2026-06-17

Executive brief

WorkScout-Core is a WordPress plugin used to provide core functionality for job board and directory websites. A security flaw allows unauthenticated individuals to delete arbitrary files from the web server. This could lead to a complete website outage if critical system files are removed, or allow attackers to bypass security controls by deleting configuration files.

Technical details

A path traversal vulnerability (CWE-22) exists in the WorkScout-Core plugin for WordPress up to and including version 1.7.11. The flaw allows an unauthenticated remote attacker to delete arbitrary files on the server by manipulating file path parameters. This occurs due to improper limitation of a pathname to a restricted directory. Successful exploitation can lead to a denial of service by deleting core WordPress or plugin files, or potentially lead to further compromise if configuration files (like wp-config.php) are targeted. The issue is fixed in version 1.7.12.

Affected products

  • purethemes WorkScout-Core <= 1.7.11

Timeline

  • 2026-04-13: other: Vulnerability reported by researcher Nguyen Ba Khanh
  • 2026-06-15: advisory: Patchstack published advisory
  • 2026-06-17: disclosed: NVD publication date

References

Related threats