CVE-2025-69101: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-69101 is an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288) in the AmentoTech Workreap Core WordPress plugin that allows unauthenticated attackers to perform authentication abuse, potentially leading to account takeover. It affects Workreap Core versions up to and including 3.4.1 (initially disclosed as affecting up to 3.4.0, later updated to include 3.4.1). The vulnerability was first reported by Patchstack on January 22, 2026, with the affected version range updated on April 1, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical), assigned by CISA-ADP (NVD, Patchstack).

Technical details

The root cause is classified as CWE-288 — Authentication Bypass Using an Alternate Path or Channel — meaning the plugin fails to properly enforce authentication controls, allowing an attacker to reach privileged functionality through an unprotected alternative path or channel. The attack vector is network-based, requires no privileges, no user interaction, and has low attack complexity, making it trivially exploitable by any remote unauthenticated attacker. The vulnerability enables "Authentication Abuse," which in the context of the Workreap Core plugin (a freelance marketplace plugin for WordPress) likely allows an attacker to authenticate as or impersonate arbitrary user accounts, resulting in account takeover (NVD, Patchstack).

Impact

Successful exploitation grants an unauthenticated remote attacker full control over arbitrary user accounts on affected WordPress sites running the Workreap Core plugin, with high impact to confidentiality, integrity, and availability. An attacker could take over administrator accounts, access sensitive user and business data stored in the freelance marketplace platform, modify or delete content, and potentially pivot to full WordPress site compromise. The broad scope of impact — including all three CIA triad components rated HIGH — makes this a severe risk for any site using the affected plugin versions (NVD).

Exploitability

No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term relative to other CVEs. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the critical CVSS score and zero-prerequisite attack conditions make it a high-priority target if exploit details become public (NVD, Feedly).

Mitigation and workarounds

Users should update the Workreap Core plugin to a version beyond 3.4.1, which is the last confirmed vulnerable release. Site administrators should check the WordPress plugin repository or the AmentoTech vendor site for a patched release and apply it immediately. As an interim measure, consider disabling the Workreap Core plugin on internet-facing WordPress installations until a patch is applied, and review user accounts for unauthorized access or privilege changes (NVD, Patchstack).

Community reactions

The vulnerability was noted in Wordfence's weekly WordPress vulnerability report for the week of January 12–18, 2026, and was included in a CISA vulnerability summary for the week of January 19, 2026, indicating it received standard industry tracking attention. No notable individual researcher commentary or significant social media discussion has been identified beyond routine vulnerability aggregation (Wordfence Blog, RedPacket Security).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management