PT-2025-25281 · WordPress · Workreap

Friderika Baranyai

·

Published

2025-06-12

·

Updated

2025-07-10

·

CVE-2025-5012

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Workreap plugin for WordPress versions up to and including 3.3.2
Description The issue arises from missing file type validation in the workreap temp upload to media function, allowing authenticated attackers with Subscriber-level access or higher to upload arbitrary files to the server of the affected site. This could potentially enable remote code execution.
Recommendations For Workreap plugin for WordPress versions up to and including 3.3.2, update to a version higher than 3.3.2 to resolve the issue. As a temporary workaround, consider restricting access to the workreap temp upload to media function to minimize the risk of exploitation.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-5012

Affected Products

Workreap