Authentication vulnerability in Workreap 3.2.5

The Workreap plugin, which is used on WordPress websites, has a security vulnerability that allows people to gain access to other user’s accounts. This can happen when someone uses a social media account to login or when they update their profile information, like their password. Attackers who are not logged in can use this vulnerability to login as any user if they know their email address, or change the password of any user, including administrators. This can give them access to the user’s account. Please note that this vulnerability was partially fixed in version 3.2.5.

Detected in:

Workreap - Freelance Marketplace and Directory WordPress Theme fixed vulnerable versions: >= * <= 3.2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.