Junglewise Threat Intelligence

CVE-2026-57786: purethemes WorkScout-Core CSRF authentication bypass

CVE-2026-57786 · Severity: high · CVSS 8.8 · Published 2026-07-13

Executive brief

WorkScout-Core is a WordPress plugin used to provide core functionality for job board websites. A security flaw allows an attacker to trick a site administrator into performing unintended actions, which can lead to the attacker bypassing authentication and gaining unauthorized access to the site. This could result in a full takeover of the website, data theft, or service disruption.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the purethemes WorkScout-Core plugin for WordPress (versions up to and including 1.7.08). The vulnerability stems from a lack of proper nonce validation or equivalent CSRF protections within the plugin's authentication-related functions. An unauthenticated remote attacker can exploit this by inducing a logged-in administrator or high-privileged user to visit a malicious link or submit a crafted form. Successful exploitation allows the attacker to bypass authentication mechanisms, potentially leading to complete site compromise. As of the advisory date, no official patch has been released.

Affected products

  • purethemes WorkScout-Core <= 1.7.08

Timeline

  • 2026-01-31: disclosed: Reported by Phat RiO to Patchstack
  • 2026-07-02: advisory: Patchstack published advisory details
  • 2026-07-13: advisory: CVE published to NVD dataset

References

Related threats