Amentotech's vulnerability footprint centers on Workreap, a freelance marketplace and project-management platform, and skews strongly toward critical-severity outcomes reflecting the platform's web-application nature and exposure of user authentication, authorization, and data-handling functions. The vendor's disclosures frequently acquire public exploit code and recur through authentication bypasses, missing authorization checks, unrestricted file uploads, and cross-site request forgery vulnerabilities—classic web-application attack vectors that compound on a multi-tenant marketplace architecture where privilege separation is essential. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amentotech over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24499CRITICAL The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request | Aug 9, 2021 | 9.8 | 81 | NO | YES |
CVE-2025-4973CRITICAL The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. | Jun 12, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-5012HIGH The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the | Jun 12, 2025 | 8.8 | 26 | NO | NO |
CVE-2022-3846HIGH The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notifi | Dec 5, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-24501HIGH The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifyin | Aug 9, 2021 | 8.1 | 25 | NO | NO |
CVE-2021-24500HIGH Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. | Aug 9, 2021 | 8.1 | 25 | NO | NO |
CVE-2024-13446CRITICAL The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly val | Mar 12, 2025 | 9.8 | 24 | NO | NO |
CVE-2022-4239MEDIUM The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the | Dec 26, 2022 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amentotech.
Media articles that mention a CVE ID that affects a product developed by Amentotech — matched by CVE ID, not by vendor name.