Executive brief
WorkScout-Core is a WordPress plugin used to provide core functionality for job board websites. A security flaw allows an attacker to trick a site administrator into performing unintended actions, which can lead to the attacker bypassing authentication and gaining unauthorized access to the site. This could result in a full takeover of the website, data theft, or service disruption.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the purethemes WorkScout-Core plugin for WordPress (versions up to and including 1.7.08). The vulnerability stems from a lack of proper nonce validation or equivalent CSRF protections within the plugin's authentication-related functions. An unauthenticated remote attacker can exploit this by inducing a logged-in administrator or high-privileged user to visit a malicious link or submit a crafted form. Successful exploitation allows the attacker to bypass authentication mechanisms, potentially leading to complete site compromise. As of the advisory date, no official patch has been released.
Affected products
- purethemes WorkScout-Core <= 1.7.08
Timeline
- 2026-01-31: disclosed: Reported by Phat RiO to Patchstack
- 2026-07-02: advisory: Patchstack published advisory details
- 2026-07-13: advisory: CVE published to NVD dataset