Workreap (theme's plugin) <= 3.3.6 - Authenticated (Subscriber+) SQL Injection
medium
The Workreap (theme's plugin) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level ac...
- CVSS:
- 6.5
- Affected:
- up to 3.3.6
- Fix:
- No patched version reported
- Disclosed:
- Jan 8, 2026
CVE-2025-22728 on NVD →
Workreap [workreap] <= 3.3.6 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows SQL Injection.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.6.
- Affected:
- up to 3.3.6
- Fix:
- No patched version reported
- Disclosed:
- Jan 8, 2026
CVE-2025-22728 on NVD →
Workreap <= 3.3.5 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The Workreap plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to r...
- CVSS:
- 8.1
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.6
- Disclosed:
- Sep 26, 2025
CVE-2025-59566 on NVD →
Workreap <= 3.3.2 - Authenticated (Subscriber+) Arbitrary File Upload via 'workreap_temp_upload_to_media'
high
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'workreap_temp_upload_to_media' function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, wi...
- CVSS:
- 8.8
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.3
- Disclosed:
- Jun 11, 2025
CVE-2025-5012 on NVD →
Workreap <= 3.3.1 - Authentication Bypass via 'workreap_verify_user_account'
critical
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to the plugin not properly verifying a user's identity prior to logging them in when verifying an account with an email address...
- CVSS:
- 9.8
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Jun 11, 2025
CVE-2025-4973 on NVD →
Workreap [workreap] < 3.2.6
unknown
[en] The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly validating a user's identity prior to (1) performing a social auto-login or (2) updating their profile details (e.g. password). This makes...
- Affected:
- up to 3.2.6
- Fixed in:
- 3.2.6
- Disclosed:
- Mar 12, 2025
CVE-2024-13446 on NVD →
Workreap <= 3.2.5 - Unauthenticated Privilege Escalation via Account Takeover
critical
The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly validating a user's identity prior to (1) performing a social auto-login or (2) updating their profile details (e.g. password). This makes it p...
- CVSS:
- 9.8
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.6
- Disclosed:
- Mar 11, 2025
CVE-2024-13446 on NVD →
Workreap [workreap] < 3.3.3
unknown
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
CVE-2025-5012 on NVD →
Workreap [workreap] < 3.3.2
unknown
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.2
CVE-2025-4973 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database