← WordPress Vulnerabilities
WordPress security by component

Workreap (theme's plugin)

Workreap (theme's plugin) is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Jan 08, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: workreap

CVE-2025-22728: Workreap (theme's plugin): SQL injection

Workreap (theme's plugin) is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.

PublishedJan 08, 2026
Safe version guidanceSee mitigation notes
Safe version
Jan 08, 2026 CVE-2025-22728
Workreap (theme's plugin): SQL injection
Workreap (theme's plugin) is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Oct 22, 2025 CVE-2025-59566
Workreap (theme's plugin): Filesystem traversal
Workreap (theme's plugin) is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.7
NVDPending
Jun 12, 2025 CVE-2025-5012
Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace: Dangerous file upload
Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace is affected by dangerous file upload. Exploitation requires at least subscriber-level access. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.8
NVDPending
Jun 12, 2025 CVE-2025-4973
Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace: Privilege escalation or authentication bypass
Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Mar 12, 2025 CVE-2024-13446
Workreap: Privilege escalation or authentication bypass
Workreap is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Dec 26, 2022 CVE-2022-4239
Workreap: A security weakness
Workreap is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Dec 05, 2022 CVE-2022-3846
Workreap: A security weakness
Workreap is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Aug 09, 2021 CVE-2021-24501
Workreap: A security weakness
Workreap is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.1
NVD8.1
Aug 09, 2021 CVE-2021-24500
Workreap: Cross-site request forgery
Workreap is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.1
NVD8.1
Aug 09, 2021 CVE-2021-24499
Workreap: A security weakness
Workreap is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8