
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69101 is an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288) in the AmentoTech Workreap Core WordPress plugin that allows unauthenticated attackers to perform authentication abuse, potentially leading to account takeover. It affects Workreap Core versions up to and including 3.4.1 (initially disclosed as affecting up to 3.4.0, later updated to include 3.4.1). The vulnerability was first reported by Patchstack on January 22, 2026, with the affected version range updated on April 1, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical), assigned by CISA-ADP (NVD, Patchstack).
The root cause is classified as CWE-288 — Authentication Bypass Using an Alternate Path or Channel — meaning the plugin fails to properly enforce authentication controls, allowing an attacker to reach privileged functionality through an unprotected alternative path or channel. The attack vector is network-based, requires no privileges, no user interaction, and has low attack complexity, making it trivially exploitable by any remote unauthenticated attacker. The vulnerability enables "Authentication Abuse," which in the context of the Workreap Core plugin (a freelance marketplace plugin for WordPress) likely allows an attacker to authenticate as or impersonate arbitrary user accounts, resulting in account takeover (NVD, Patchstack).
Successful exploitation grants an unauthenticated remote attacker full control over arbitrary user accounts on affected WordPress sites running the Workreap Core plugin, with high impact to confidentiality, integrity, and availability. An attacker could take over administrator accounts, access sensitive user and business data stored in the freelance marketplace platform, modify or delete content, and potentially pivot to full WordPress site compromise. The broad scope of impact — including all three CIA triad components rated HIGH — makes this a severe risk for any site using the affected plugin versions (NVD).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term relative to other CVEs. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the critical CVSS score and zero-prerequisite attack conditions make it a high-priority target if exploit details become public (NVD, Feedly).
Users should update the Workreap Core plugin to a version beyond 3.4.1, which is the last confirmed vulnerable release. Site administrators should check the WordPress plugin repository or the AmentoTech vendor site for a patched release and apply it immediately. As an interim measure, consider disabling the Workreap Core plugin on internet-facing WordPress installations until a patch is applied, and review user accounts for unauthorized access or privilege changes (NVD, Patchstack).
The vulnerability was noted in Wordfence's weekly WordPress vulnerability report for the week of January 12–18, 2026, and was included in a CISA vulnerability summary for the week of January 19, 2026, indicating it received standard industry tracking attention. No notable individual researcher commentary or significant social media discussion has been identified beyond routine vulnerability aggregation (Wordfence Blog, RedPacket Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."