The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HAmentotech Workreap
APPAmentotech< 2.2.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2025-4973CRITICAL9.8PL ✓same product
Authentication Bypass w pluginie Workreap dla WordPress (do wersji 3.3.1)
CVE-2024-13446CRITICAL9.8PL ✓same product
Workreap WordPress Plugin — przejęcie konta i eskalacja uprawnień
CVE-2021-24499CRITICAL9.8PL ✓same product
Nieuwierzytelniony upload plików w motywie WordPress Workreap
CVE-2025-5012HIGH8.8same product
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable...
CVE-2022-3846HIGH7.5same product
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible ...