HIGH🇬🇧 English

CVE-2021-24500

CVSS 8.1v3.1pub. 2021-08-09upd. 2024-11-21

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
  • Amentotech Workreap

    APP
    Amentotech
    < 2.2.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
IDOR
CWE
Referencje

Powiązane podatności

CVE-2025-4973CRITICAL9.8PL ✓ten sam produkt

Authentication Bypass w pluginie Workreap dla WordPress (do wersji 3.3.1)

CVE-2024-13446CRITICAL9.8PL ✓ten sam produkt

Workreap WordPress Plugin — przejęcie konta i eskalacja uprawnień

CVE-2021-24499CRITICAL9.8PL ✓ten sam produkt

Nieuwierzytelniony upload plików w motywie WordPress Workreap

CVE-2025-5012HIGH8.8ten sam produkt

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable...

CVE-2022-3846HIGH7.5ten sam produkt

The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible ...