📦 Workreap

by Amentotech

🔍 What is Workreap?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-4973

CRITICAL CVSS 9.8 Jun 12, 2025

The Workreap WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any registered user, including administrators, by knowing their email addres...

CVE-2024-13446

CRITICAL CVSS 9.8 Mar 12, 2025

The Workreap WordPress plugin allows unauthenticated attackers to take over any user account, including administrators, by exploiting insufficient identity validation during social auto-login and prof...

CVE-2021-24499

CRITICAL CVSS 9.8 Aug 9, 2021

This vulnerability allows unauthenticated attackers to upload arbitrary files, including PHP scripts, to WordPress sites using the Workreap theme. The flaw exists in AJAX endpoints that lack authentic...

CVE-2021-24501

HIGH CVSS 8.1 Aug 9, 2021

This vulnerability in the Workreap WordPress theme allows authenticated users to modify or delete objects belonging to other users due to missing authorization checks in AJAX actions. It affects WordP...