Workreap Core <= 3.4.0 - Authentication Bypass
criticalThe Workreap Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.4.0. This makes it possible for unauthenticated attackers to authenticate as other users without verifying their identity.
- CVSS:
- 9.8
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 15, 2026