Workreap <= 3.3.1 - Authentication Bypass via 'workreap_verify_user_account'

2025-06-11 16:31
Foxyyy

Strategic Overview

Status
Patched in 3.3.2
Affected PluginWorkreap
Affected Version<= 3.3.1
CVSS9.8Critical
CVECVE-2025-4973
View all Workreap vulnerabilities

Vulnerability Overview

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to the plugin not properly verifying a user's identity prior to logging them in when verifying an account with an email address. This makes it possible for unauthenticated attackers to log in as registered users, including administrators, if they know user's email address. This is only exploitable fi the user's confirmation_key has not already been set by the plugin.

Technical Analysis

REMEDIATION: Update to version 3.3.2, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C