plugin

Workreap Vulnerabilities

9 known security issues reported for the Workreap WordPress plugin. Most recent disclosed Jan 8, 2026.

2 critical 2 high 1 medium

Running Workreap on your site? Check whether your installed version is affected.

Scan your site free

Workreap (theme's plugin) <= 3.3.6 - Authenticated (Subscriber+) SQL Injection

medium

The Workreap (theme's plugin) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level ac...

CVSS:
6.5
Affected:
up to 3.3.6
Fix:
No patched version reported
Disclosed:
Jan 8, 2026

CVE-2025-22728 on NVD →

Workreap [workreap] <= 3.3.6 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows SQL Injection.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.6.

Affected:
up to 3.3.6
Fix:
No patched version reported
Disclosed:
Jan 8, 2026

CVE-2025-22728 on NVD →

Workreap <= 3.3.5 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The Workreap plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to r...

CVSS:
8.1
Affected:
up to 3.3.5
Fixed in:
3.3.6
Disclosed:
Sep 26, 2025

CVE-2025-59566 on NVD →

Workreap <= 3.3.2 - Authenticated (Subscriber+) Arbitrary File Upload via 'workreap_temp_upload_to_media'

high

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'workreap_temp_upload_to_media' function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, wi...

CVSS:
8.8
Affected:
up to 3.3.2
Fixed in:
3.3.3
Disclosed:
Jun 11, 2025

CVE-2025-5012 on NVD →

Workreap <= 3.3.1 - Authentication Bypass via 'workreap_verify_user_account'

critical

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to the plugin not properly verifying a user's identity prior to logging them in when verifying an account with an email address...

CVSS:
9.8
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Jun 11, 2025

CVE-2025-4973 on NVD →

Workreap [workreap] < 3.2.6

unknown

[en] The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly validating a user's identity prior to (1) performing a social auto-login or (2) updating their profile details (e.g. password). This makes...

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Mar 12, 2025

CVE-2024-13446 on NVD →

Workreap <= 3.2.5 - Unauthenticated Privilege Escalation via Account Takeover

critical

The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly validating a user's identity prior to (1) performing a social auto-login or (2) updating their profile details (e.g. password). This makes it p...

CVSS:
9.8
Affected:
up to 3.2.5
Fixed in:
3.2.6
Disclosed:
Mar 11, 2025

CVE-2024-13446 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database