Skip to content
Noroxi

AmentoTech records

8 published records for vendor amentotech.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
12.5%
Median publish → KEV
No record has entered KEV

All records

8 records
  • Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution

    CriticalCVSS 9.8Proof of conceptEPSS 60%

    amentotech · workreapAug 9, 2021

  • CVE-2025-4973
    39Monitor

    Workreap <= 3.3.1 - Authentication Bypass via 'workreap_verify_user_account'

    CriticalCVSS 9.8No exploitEPSS 0%

    amentotech · workreapJun 12, 2025

  • Workreap <= 3.2.5 - Unauthenticated Privilege Escalation via Account Takeover

    CriticalCVSS 9.8No exploitEPSS 0%

    amentotech · workreapMar 12, 2025

  • CVE-2025-5012
    35Monitor

    Workreap <= 3.3.2 - Authenticated (Subscriber+) Arbitrary File Upload via 'workreap_temp_upload_to_media'

    HighCVSS 8.8No exploitEPSS 1%

    amentotech · workreapJun 12, 2025

  • Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions

    HighCVSS 8.1No exploitEPSS 1%

    amentotech · workreapAug 9, 2021

  • Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities

    HighCVSS 8.1No exploitEPSS 1%

    amentotech · workreapAug 9, 2021

  • CVE-2022-3846
    30Monitor

    Workreap - Freelance Marketplace and Directory < 2.6.3 - Subscriber+ Private Message Disclosure via IDOR

    HighCVSS 7.5No exploitEPSS 1%

    amentotech · workreapDec 5, 2022

  • CVE-2022-4239
    26Monitor

    Workreap < 2.6.4 - Subscriber+ Arbitrary Posts Deletion via IDOR

    MediumCVSS 6.5No exploitEPSS 1%

    amentotech · workreapDec 26, 2022