Vulnerability record · CVE-2021-24499 · published 9 August 2021
CVE-2021-24499: Workreap WordPress theme unauthenticated arbitrary file upload
Amentotech · Workreap
The Workreap WordPress theme before 2.2.2 exposes AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader that perform no nonce check and no user validation. They accept arbitrary files into uploads/workreap-temp without sanitization or type validation, so an unauthenticated visitor can place executable PHP code on the server.
Description
The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution via arbitrary file upload with a 9.8 CVSS score and high EPSS probability.
What it is
The Workreap WordPress theme before 2.2.2 exposes AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader that perform no nonce check and no user validation. They accept arbitrary files into uploads/workreap-temp without sanitization or type validation, so an unauthenticated visitor can place executable PHP code on the server.
Impact
An attacker can upload and execute arbitrary PHP, leading to remote code execution and full compromise of the WordPress site and its host. CVSS 3.1 base score is 9.8 (critical).
Attack surface
Reached over the network via the theme's AJAX endpoints; the CVSS vector AV:N/AC:L/PR:N/UI:N confirms no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS 30-day probability is 0.60113 (99.1st percentile) and multiple references are tagged Exploit, including a public shell-upload writeup.
What to do
- Update the Workreap theme to 2.2.2 or later immediately.
- If patching is not possible, disable or block the workreap_award_temp_file_uploader and workreap_temp_file_uploader AJAX actions.
- Block direct web access to the uploads/workreap-temp directory and deny execution of PHP files there.
- Audit the uploads/workreap-temp directory for unexpected files and remove any PHP content.
- Add WAF rules to reject file uploads to those AJAX endpoints from unauthenticated clients.
Detection
- Monitor web logs for POST requests to admin-ajax.php with action=workreap_award_temp_file_uploader or action=workreap_temp_file_uploader.
- Alert on new files appearing in wp-content/uploads/workreap-temp, especially .php or other executable extensions.
- Hunt for outbound or inbound requests to files under uploads/workreap-temp that return 200 and execute server-side code.
- Review file integrity monitoring for unexpected PHP files in the uploads tree.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/172876/WordPress-Workreap-2.2.2-Shell-Upload.html | |
| https://jetpack.com/2021/07/07/multiple-vulnerabilities-in-workreap-theme/ | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/74611d5f-afba-42ae-bc19-777cdf2808cb | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/172876/WordPress-Workreap-2.2.2-Shell-Upload.html | |
| https://jetpack.com/2021/07/07/multiple-vulnerabilities-in-workreap-theme/ | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/74611d5f-afba-42ae-bc19-777cdf2808cb | ExploitThird Party Advisory |
Track CVE-2021-24499 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-24499), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.