The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HAmentotech Workreap
APPAmentotech< 2.2.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2025-4973CRITICAL9.8PL ✓ten sam produkt
Authentication Bypass w pluginie Workreap dla WordPress (do wersji 3.3.1)
CVE-2024-13446CRITICAL9.8PL ✓ten sam produkt
Workreap WordPress Plugin — przejęcie konta i eskalacja uprawnień
CVE-2021-24499CRITICAL9.8PL ✓ten sam produkt
Nieuwierzytelniony upload plików w motywie WordPress Workreap
CVE-2025-5012HIGH8.8ten sam produkt
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable...
CVE-2022-3846HIGH7.5ten sam produkt
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible ...