theme

Workreap Vulnerabilities

5 known security issues reported for the Workreap WordPress theme. Most recent disclosed Dec 2, 2022.

1 critical 2 high 2 medium

Running Workreap on your site? Check whether your installed version is affected.

Scan your site free

Workreap <= 2.6.3 - Insecure Direct Object Reference

medium

The Workreap theme for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 2.6.3. This is due to missing validation on if an addon service belongs to an individual making a request to the workreap_addons_service_remove action. This makes it possible for authenticated attackers...

CVSS:
5.4
Affected:
up to 2.6.3
Fixed in:
2.6.4
Disclosed:
Dec 2, 2022

CVE-2022-4239 on NVD →

Workreap < 2.6.3 - Insecure Direct Objection Reference to Private Message Disclosure

medium

The Workreap theme for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, but not including, 2.6.3. This makes it possible for authenticated attackers, with subscriber-level access or higher, to read arbitrary user notifications.

CVSS:
5.4
Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Nov 12, 2022

CVE-2022-3846 on NVD →

Workreap - Freelance Marketplace and Directory WordPress Theme < 2.2.2 - Arbitrary File Upload

critical

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded...

CVSS:
9.8
Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Jul 2, 2021

CVE-2021-24499 on NVD →

Workreap < 2.2.2 - Cross-Site Request Forgery

high

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitra...

CVSS:
8.1
Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Jul 2, 2021

CVE-2021-24500 on NVD →

Workreap Theme < 2.2.2 - Authorization Bypass

high

The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site.

CVSS:
8.1
Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Jun 29, 2021

CVE-2021-24501 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database