The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly validating a user's identity prior to (1) performing a social auto-login or (2) updating their profile details (e.g. password). This makes it possible for unauthenticated attackers to (1) login as an arbitrary user if their email address is known or (2) change an arbitrary user's password, including administrators, and leverage that to gain access to their account. NOTE: This vulnerability was partially fixed in version 3.2.5.
History

Wed, 02 Apr 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Amentotech
Amentotech workreap
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:amentotech:workreap:*:*:*:*:*:wordpress:*:*
Vendors & Products Amentotech
Amentotech workreap

Wed, 12 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Mar 2025 09:45:00 +0000

Type Values Removed Values Added
Description The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly validating a user's identity prior to (1) performing a social auto-login or (2) updating their profile details (e.g. password). This makes it possible for unauthenticated attackers to (1) login as an arbitrary user if their email address is known or (2) change an arbitrary user's password, including administrators, and leverage that to gain access to their account. NOTE: This vulnerability was partially fixed in version 3.2.5.
Title Workreap <= 3.2.5 - Unauthenticated Privilege Escalation via Account Takeover
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-03-12T14:20:41.049Z

Reserved: 2025-01-15T22:03:36.460Z

Link: CVE-2024-13446

cve-icon Vulnrichment

Updated: 2025-03-12T14:19:51.870Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-12T10:15:14.620

Modified: 2025-04-02T12:39:50.137

Link: CVE-2024-13446

cve-icon Redhat

No data.