Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-4973 The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versio… Workreap 3.3.2+ Fix from $2,3002025-06-12 HIGH 8.8 CVE-2025-5012 The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missi… Workreap 3.3.3+ Fix from $1,9502025-06-12 CRITICAL 9.8 CVE-2024-13446 The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due… Workreap 3.2.6+ Fix from $2,3002025-03-12 MEDIUM 6.5 CVE-2022-4239 The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addo… Workreap 2.6.4+ Fix from $1,6002022-12-26 HIGH 7.5 CVE-2022-3846 The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employ… Workreap 2.6.3+ Fix from $1,9502022-12-05 CRITICAL 9.8 CVE-2021-24499EPSS 60% The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks… Workreap 2.2.2+ Fix from $2,3002021-08-09 HIGH 8.1 CVE-2021-24500 Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object refer… Workreap 2.2.2+ Fix from $1,9502021-08-09 HIGH 8.1 CVE-2021-24501 The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform criti… Workreap 2.2.2+ Fix from $1,9502021-08-09