
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-22728 is a SQL Injection vulnerability in the AmentoTech Workreap WordPress plugin (a companion plugin for the Workreap freelance marketplace theme). The flaw allows authenticated attackers with at least Subscriber-level privileges to inject malicious SQL commands into database queries. It affects all versions of the Workreap plugin through 3.3.6. The vulnerability was reported by researcher "Bonds" on August 24, 2025, and publicly disclosed by Patchstack on January 8, 2026. It carries a CVSS v3.1 base score of 8.5 (High), as assessed by Patchstack (Patchstack).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is incorporated into database queries without adequate sanitization or parameterization. Exploitation requires a low-privilege authenticated account (Subscriber level or above), no user interaction, and network access to the target WordPress installation. The changed scope in the CVSS vector indicates that a successful attack can impact resources beyond the vulnerable component itself — specifically the underlying database. No public proof-of-concept code or detailed technical write-up describing the specific vulnerable parameter or endpoint has been published as of the disclosure date (Patchstack).
Successful exploitation allows an attacker to directly interact with the WordPress site's database, enabling unauthorized reading of sensitive data (e.g., user credentials, personal information, private content), and potentially limited availability disruption. The changed scope means the impact extends beyond the plugin itself to the broader database environment. While integrity impact is rated None in the Patchstack CVSS assessment, confidentiality impact is rated High, making data exfiltration the primary risk. In a worst-case scenario, exposed database credentials or sensitive records could facilitate further lateral movement or account takeover (Patchstack).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the disclosure date. The EPSS score is approximately 0.021% (0.000210), indicating a low current probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies this as high priority, noting that SQL injection vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
As of the disclosure date, no official patch from AmentoTech has been released for the Workreap plugin. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is available. Site administrators should consider disabling the Workreap plugin if it is not critical to operations, implement a Web Application Firewall (WAF) with SQL injection detection rules, and restrict database user permissions to the minimum required. Monitoring database activity for anomalous queries is also recommended. Once an updated version above 3.3.6 becomes available, upgrading immediately is the definitive remediation (Patchstack).
Wordfence included CVE-2025-22728 in its weekly WordPress vulnerability report for January 5–11, 2026, highlighting it among notable plugin vulnerabilities of that period (Wordfence Blog). The vulnerability received limited broader media attention, consistent with its status as a plugin-specific issue without a public exploit.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."