VendorsAmentotechworkreapany version
Vulnerabilities

Amentotech Workreap any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2021-24499
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
Published 2021-08-09 · Modified
9.81 PoCEPSS 0.601
CVE-2025-4973
Workreap <= 3.3.1 - Authentication Bypass via 'workreap_verify_user_account'
Published 2025-06-12 · Analyzed
9.8EPSS 0.005
CVE-2024-13446
Workreap <= 3.2.5 - Unauthenticated Privilege Escalation via Account Takeover
Published 2025-03-12 · Analyzed
9.8EPSS 0.004
CVE-2025-5012
Workreap <= 3.3.2 - Authenticated (Subscriber+) Arbitrary File Upload via 'workreap_temp_upload_to_media'
Published 2025-06-12 · Analyzed
8.8EPSS 0.006
CVE-2021-24501
Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions
Published 2021-08-09 · Modified
8.1EPSS 0.013
CVE-2021-24500
Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities
Published 2021-08-09 · Modified
8.1EPSS 0.006
CVE-2022-3846
Workreap - Freelance Marketplace and Directory < 2.6.3 - Subscriber+ Private Message Disclosure via IDOR
Published 2022-12-05 · Modified
7.5EPSS 0.008
CVE-2022-4239
Workreap < 2.6.4 - Subscriber+ Arbitrary Posts Deletion via IDOR
Published 2022-12-26 · Modified
6.5EPSS 0.006