← Vulnerability feed

Vulnerability record · CVE-2021-24499 · published 9 August 2021

CVE-2021-24499: Workreap WordPress theme unauthenticated arbitrary file upload

Amentotech · Workreap

The Workreap WordPress theme before 2.2.2 exposes AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader that perform no nonce check and no user validation. They accept arbitrary files into uploads/workreap-temp without sanitization or type validation, so an unauthenticated visitor can place executable PHP code on the server.

9.8 CVSS 3.1 Critical EPSS 60% · top 0.9% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution via arbitrary file upload with a 9.8 CVSS score and high EPSS probability.

What it is

The Workreap WordPress theme before 2.2.2 exposes AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader that perform no nonce check and no user validation. They accept arbitrary files into uploads/workreap-temp without sanitization or type validation, so an unauthenticated visitor can place executable PHP code on the server.

Impact

An attacker can upload and execute arbitrary PHP, leading to remote code execution and full compromise of the WordPress site and its host. CVSS 3.1 base score is 9.8 (critical).

Attack surface

Reached over the network via the theme's AJAX endpoints; the CVSS vector AV:N/AC:L/PR:N/UI:N confirms no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS 30-day probability is 0.60113 (99.1st percentile) and multiple references are tagged Exploit, including a public shell-upload writeup.

What to do

  • Update the Workreap theme to 2.2.2 or later immediately.
  • If patching is not possible, disable or block the workreap_award_temp_file_uploader and workreap_temp_file_uploader AJAX actions.
  • Block direct web access to the uploads/workreap-temp directory and deny execution of PHP files there.
  • Audit the uploads/workreap-temp directory for unexpected files and remove any PHP content.
  • Add WAF rules to reject file uploads to those AJAX endpoints from unauthenticated clients.

Detection

  • Monitor web logs for POST requests to admin-ajax.php with action=workreap_award_temp_file_uploader or action=workreap_temp_file_uploader.
  • Alert on new files appearing in wp-content/uploads/workreap-temp, especially .php or other executable extensions.
  • Hunt for outbound or inbound requests to files under uploads/workreap-temp that return 200 and execute server-side code.
  • Review file integrity monitoring for unexpected PHP files in the uploads tree.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-24499 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-4973Amentotech workreap authentication bypass via alternate path vulnerabilityThe Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versio…EPSS 0.48%9.8CVE-2024-13446Amentotech workreap authentication bypass via alternate path vulnerabilityThe Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due…EPSS 0.43%8.8CVE-2025-5012Amentotech workreap unrestricted file upload vulnerabilityThe Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missi…EPSS 0.60%8.1CVE-2021-24500Amentotech workreap improper access control vulnerabilitySeveral AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object refer…EPSS 0.65%8.1CVE-2021-24501Amentotech workreap missing authorization vulnerabilityThe Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform criti…EPSS 1.3%7.5CVE-2022-3846Amentotech workreap vulnerabilityThe Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employ…EPSS 0.79%6.5CVE-2022-4239Amentotech workreap vulnerabilityThe Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addo…EPSS 0.59%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2021-24499), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.