CVE-2022-4239
The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any…
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.59% probability · 47th percentile
- CISA KEV
- Not listed
- Affected
- amentotech/workreap
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/1c163987-fb53-43f7-bbff-1c2d8c0d694cExploit, Third Party Advisory
- https://wpscan.com/vulnerability/1c163987-fb53-43f7-bbff-1c2d8c0d694cExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.