Arbitrary File Upload Vulnerability in Workreap - Freelance Marketplace Plugin
CVE-2025-5012
8.8HIGH
What is CVE-2025-5012?
The Workreap plugin for WordPress contains a vulnerability allowing authenticated users, including those with Subscriber-level access, to exploit missing file type validations in the 'workreap_temp_upload_to_media' function. This flaw enables the upload of arbitrary files to the server, which could lead to remote code execution, compromising the integrity and security of the website.
Affected Version(s)
Workreap * <= 3.3.2