HIGH🇵🇱 Wersja polska

CVE-2021-24500

CVSS 8.1v3.1pub. 2021-08-09upd. 2024-11-21

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
  • Amentotech Workreap

    APP
    Amentotech
    < 2.2.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
IDOR
CWE
References

Related vulnerabilities

CVE-2025-4973CRITICAL9.8PL ✓same product

Authentication Bypass w pluginie Workreap dla WordPress (do wersji 3.3.1)

CVE-2024-13446CRITICAL9.8PL ✓same product

Workreap WordPress Plugin — przejęcie konta i eskalacja uprawnień

CVE-2021-24499CRITICAL9.8PL ✓same product

Nieuwierzytelniony upload plików w motywie WordPress Workreap

CVE-2025-5012HIGH8.8same product

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable...

CVE-2022-3846HIGH7.5same product

The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible ...