CVE-2021-24499
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
- Published
- Aug 9, 2021
- Updated
- Aug 3, 2024
- Assigning CNA
- WPScan
- Evidence observed
- Jun 9, 2023
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.
Sources
5- CVE-2021-24499Exploit
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
Exploit for CVE-2021-24499 targeting a specific web application vulnerability. Provides proof-of-concept code for security testing and vulnerability verification.
- CVE-2021-24499Exploit
Automated mass exploitation script for CVE-2021-24499, an unauthenticated file upload vulnerability in the Workreap WordPress theme leading to remote code execution.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.