S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24499 Scanner

CVE-2021-24499 scanner - File Upload vulnerability in Workreap theme for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24499
9.8
CVSS

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Workreap
AFFECTED< 2.2.2SAFE ✓≥ 2.2.2
Updated Aug 21, 2026View on NVD →
Detail

The Workreap WordPress theme is a specially designed theme that is used for websites that require freelance or professional services. This theme allows clients to post jobs, and freelancers can bid on projects and get hired by clients. Additionally, Workreap allows users to manage their projects, payments, and milestones in a centralized platform.

The CVE-2021-24499 vulnerability is a serious security flaw that was detected in the Workreap WordPress theme. This vulnerability lies in the AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader, which did not perform nonce checks or validate whether requests are from valid users. This allowed an unauthorized visitor to upload arbitrary files into the uploads/workreap-temp directory, creating a serious security threat.

When this vulnerability is exploited, the attacker can upload executable code, such as PHP scripts, that can harm the website by accessing sensitive data, taking control of the server, or injecting malware. This vulnerability can lead to compromising the security of a website and damaging its reputation, leading to a loss of trust among users. 

In conclusion, cybersecurity threats like CVE-2021-24499 serve as a reminder that digital assets require continuous monitoring and protection. At s4e.io, we aim to provide users with access to the latest information on the security of their digital assets. Our platform's pro features allow users to quickly and easily identify security vulnerabilities on their websites, enabling them to take proactive measures to safeguard their data, reputation, and users' trust. Trust us for your website's security today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, Workreap WordPress theme users can take the following precautions:

  • Update the Workreap theme to 2.2.2 or higher to mitigate this vulnerability.
  • Limit file upload permissions to trusted users only.
  • Use a Content Security Policy (CSP) that restricts content to only trusted sources.
  • Regularly scan the website for vulnerabilities and weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.