CRITICAL🇵🇱 Wersja polska

CVE-2025-4973

CVSS 9.8v3.1pub. 2025-06-12upd. 2025-07-10

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to the plugin not properly verifying a user's identity prior to logging them in when verifying an account with an email address. This makes it possible for unauthenticated attackers to log in as registered users, including administrators, if they know user's email address. This is only exploitable fi the user's confirmation_key has not already been set by the plugin.

🤖 AI Analysis
How it works

The plugin does not properly verify user identity during the email confirmation process. An attacker, knowing a registered user's email address, can initiate the verification process and log into their account without providing a password. The vulnerability can only be exploited when the user's `confirmation_key` field has not yet been set by the plugin.

Impact

An attacker can gain full access to the account of any registered user, including administrators, leading to complete takeover of the WordPress website — enabling data theft and modification, malicious software installation, and compromise of service integrity and availability.

Mitigation & patch

Update the Workreap plugin to version 3.3.2 or later, in which the vulnerability has been fixed (released on May 23, 2025). The patch is available from the vendor through ThemeForest.

Who is affected

Workreap plugin for WordPress in all versions up to and including 3.3.1, used together with the Workreap - Freelance Marketplace WordPress Theme.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Amentotech Workreap

    APP
    Amentotech
    < 3.3.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-13446CRITICAL9.8PL ✓same product

Workreap WordPress Plugin — przejęcie konta i eskalacja uprawnień

CVE-2021-24499CRITICAL9.8PL ✓same product

Nieuwierzytelniony upload plików w motywie WordPress Workreap

CVE-2025-5012HIGH8.8same product

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable...

CVE-2022-3846HIGH7.5same product

The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible ...

CVE-2021-24501HIGH8.1same product

The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that...