Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Workreap CRITICAL 9.8
CVE-2025-4973

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versio…

Fix: 3.3.2+
Fix from $2,300 2025-06-12
Workreap HIGH 8.8
CVE-2025-5012

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missi…

Fix: 3.3.3+
Fix from $1,950 2025-06-12
Workreap CRITICAL 9.8
CVE-2024-13446

The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due…

Fix: 3.2.6+
Fix from $2,300 2025-03-12
Workreap MEDIUM 6.5
CVE-2022-4239

The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addo…

Fix: 2.6.4+
Fix from $1,600 2022-12-26
Workreap HIGH 7.5
CVE-2022-3846

The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employ…

Fix: 2.6.3+
Fix from $1,950 2022-12-05
Workreap CRITICAL 9.8
CVE-2021-24499EPSS 60%

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks…

Fix: 2.2.2+
Fix from $2,300 2021-08-09
Workreap HIGH 8.1
CVE-2021-24500

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object refer…

Fix: 2.2.2+
Fix from $1,950 2021-08-09
Workreap HIGH 8.1
CVE-2021-24501

The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform criti…

Fix: 2.2.2+
Fix from $1,950 2021-08-09