
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-4973 is an authentication bypass vulnerability in the Workreap plugin for WordPress (used by the Workreap - Freelance Marketplace WordPress Theme), affecting all versions up to and including 3.3.1. The flaw allows unauthenticated remote attackers to log in as any registered user, including administrators, by knowing only the target user's email address — provided the user's confirmation_key has not already been set by the plugin. It was published on June 12, 2025, and carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The plugin fails to properly verify a user's identity during the email-based account verification flow: when a user confirms their account via email, the plugin logs them in without adequately validating that the requester is the legitimate account owner. An unauthenticated attacker who knows a registered user's email address can trigger this verification flow and be authenticated as that user, bypassing normal credential checks. The vulnerability is only exploitable when the target user's confirmation_key has not yet been set by the plugin (Wordfence).
Successful exploitation grants an unauthenticated attacker full authenticated access to any targeted WordPress account, including administrator-level accounts. This can result in complete site compromise — including unauthorized modification of site content, exfiltration of sensitive user data, installation of malicious plugins or backdoors, and full breach of user privacy and account integrity. The scope of impact extends to all registered users on affected WordPress installations running the vulnerable plugin (Wordfence).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Wordfence). The EPSS score is approximately 0.22%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of required privileges or user interaction make it an attractive target if exploitation details become public.
confirmation_key has not been set).wp-config.php or core WordPress files.The vendor (AmentoTech) released a patched version, Workreap 3.3.2, on May 23, 2025, which addresses this vulnerability (ThemeForest). All site operators should update the Workreap plugin to version 3.3.2 or later immediately. If an immediate update is not possible, consider temporarily disabling the plugin, auditing all user accounts for unauthorized access, resetting passwords for administrator accounts, and monitoring authentication logs for suspicious activity.
Wordfence disclosed and reported the vulnerability, including it in their weekly WordPress vulnerability report for the week of June 9–15, 2025 (Wordfence Weekly Report). The vulnerability was also summarized in Kurt Seifried's weekly vulnerability bulletin for the week of June 9, 2025 (Kurt Seifried). No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability aggregator reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."