The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to the plugin not properly verifying a user's identity prior to logging them in when verifying an account with an email address. This makes it possible for unauthenticated attackers to log in as registered users, including administrators, if they know user's email address. This is only exploitable fi the user's confirmation_key has not already been set by the plugin.
The plugin does not properly verify user identity during the email confirmation process. An attacker, knowing a registered user's email address, can initiate the verification process and log into their account without providing a password. The vulnerability can only be exploited when the user's `confirmation_key` field has not yet been set by the plugin.
An attacker can gain full access to the account of any registered user, including administrators, leading to complete takeover of the WordPress website — enabling data theft and modification, malicious software installation, and compromise of service integrity and availability.
Update the Workreap plugin to version 3.3.2 or later, in which the vulnerability has been fixed (released on May 23, 2025). The patch is available from the vendor through ThemeForest.
Workreap plugin for WordPress in all versions up to and including 3.3.1, used together with the Workreap - Freelance Marketplace WordPress Theme.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAmentotech Workreap
APPAmentotech< 3.3.2
Related vulnerabilities
Workreap WordPress Plugin — przejęcie konta i eskalacja uprawnień
Nieuwierzytelniony upload plików w motywie WordPress Workreap
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable...
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible ...
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that...