All 8 CVE vulnerabilities found in Workreap, with AI-generated Chinese analysis, references, and POCs.
Vendor: Unknown
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-4973 | Workreap <= 3.3.1 - Authentication Bypass via 'workreap_verify_user_account' CWE-288 | 9.8 | Critical | 2025-06-12 |
| CVE-2025-5012 | Workreap <= 3.3.2 - Authenticated (Subscriber+) Arbitrary File Upload via 'workreap_temp_upload_to_media' CWE-434 | 8.8 | High | 2025-06-12 |
| CVE-2024-13446 | Workreap <= 3.2.5 - Unauthenticated Privilege Escalation via Account Takeover CWE-288 | 9.8 | Critical | 2025-03-12 |
| CVE-2022-4239 | Workreap < 2.6.4 - Subscriber+ Arbitrary Posts Deletion via IDOR | 6.5 | - | 2022-12-26 |
| CVE-2022-3846 | Workreap - Freelance Marketplace and Directory < 2.6.3 - Subscriber+ Private Message Disclosure via IDOR | 5.3 | - | 2022-12-05 |
| CVE-2021-24501 | Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions CWE-283 | 6.5 | - | 2021-08-09 |
| CVE-2021-24500 | Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities CWE-283 | 8.1 | - | 2021-08-09 |
| CVE-2021-24499 | Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution CWE-434 | 9.8 | - | 2021-08-09 |
All 8 known CVE vulnerabilities affecting Workreap with full Chinese analysis, references, and POCs where available.