CVE-2025-4973
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-4973 is an authentication bypass vulnerability in the Workreap plugin for WordPress (used by the Workreap - Freelance Marketplace WordPress Theme), affecting all versions up to and including 3.3.1. The flaw allows unauthenticated remote attackers to log in as any registered user, including administrators, by knowing only the target user's email address — provided the user's confirmation_key has not already been set by the plugin. It was published on June 12, 2025, and carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The plugin fails to properly verify a user's identity during the email-based account verification flow: when a user confirms their account via email, the plugin logs them in without adequately validating that the requester is the legitimate account owner. An unauthenticated attacker who knows a registered user's email address can trigger this verification flow and be authenticated as that user, bypassing normal credential checks. The vulnerability is only exploitable when the target user's confirmation_key has not yet been set by the plugin (Wordfence).

Impact

Successful exploitation grants an unauthenticated attacker full authenticated access to any targeted WordPress account, including administrator-level accounts. This can result in complete site compromise — including unauthorized modification of site content, exfiltration of sensitive user data, installation of malicious plugins or backdoors, and full breach of user privacy and account integrity. The scope of impact extends to all registered users on affected WordPress installations running the vulnerable plugin (Wordfence).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Wordfence). The EPSS score is approximately 0.22%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of required privileges or user interaction make it an attractive target if exploitation details become public.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Workreap plugin (version ≤ 3.3.1) via passive techniques such as checking theme/plugin metadata in page source, or using tools like WPScan to enumerate installed plugins.
  2. Obtain target email: Gather a registered user's email address (especially an administrator's) through public profile pages, contact forms, or other information disclosure on the target site.
  3. Trigger account verification flow: Craft and send an HTTP request to the plugin's email verification endpoint, supplying the known email address as the account to verify — without providing valid credentials.
  4. Bypass authentication: Because the plugin does not properly validate the requester's identity before completing the login, the server authenticates the attacker as the target user (provided the user's confirmation_key has not been set).
  5. Achieve privileged access: If the targeted account is an administrator, the attacker now has full WordPress admin access, enabling installation of backdoors, data exfiltration, or further lateral movement within the hosting environment (Wordfence).

Indicators of compromise

  • Logs: WordPress authentication logs showing successful logins from unexpected IP addresses for administrator or high-privilege accounts; repeated requests to the plugin's email verification endpoint from a single IP or user agent.
  • Network: Unusual POST requests to Workreap plugin verification endpoints (e.g., AJAX handlers related to email confirmation) originating from unknown or foreign IP addresses.
  • File System: Presence of newly installed plugins, themes, or PHP webshells not authorized by site administrators; unexpected changes to wp-config.php or core WordPress files.
  • Process/Behavior: New administrator accounts created without corresponding legitimate registration activity; unexpected changes to site settings, user roles, or installed plugins shortly after suspicious login events (Wordfence).

Mitigation and workarounds

The vendor (AmentoTech) released a patched version, Workreap 3.3.2, on May 23, 2025, which addresses this vulnerability (ThemeForest). All site operators should update the Workreap plugin to version 3.3.2 or later immediately. If an immediate update is not possible, consider temporarily disabling the plugin, auditing all user accounts for unauthorized access, resetting passwords for administrator accounts, and monitoring authentication logs for suspicious activity.

Community reactions

Wordfence disclosed and reported the vulnerability, including it in their weekly WordPress vulnerability report for the week of June 9–15, 2025 (Wordfence Weekly Report). The vulnerability was also summarized in Kurt Seifried's weekly vulnerability bulletin for the week of June 9, 2025 (Kurt Seifried). No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability aggregator reporting.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18039NONEN/A
  • essential-addons-for-elementor-lite
NoYesAug 14, 2026
CVE-2026-16810NONEN/A
  • bit-form
NoYesAug 14, 2026
CVE-2026-16739NONEN/A
  • epeken-all-kurir
NoNoAug 14, 2026
CVE-2026-15205NONEN/A
  • paymob-for-woocommerce
NoYesAug 14, 2026
CVE-2026-14290NONEN/A
  • embed-google-photos-album-easily
NoNoAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management