VYPR

Workreap Core

by WordPress

CVEs (2)

  • CVE-2026-39759CriOct 6, 2026
    risk 0.64cvss 9.9epss —

    Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.

  • CVE-2025-69101CriJan 22, 2026
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows Authentication Abuse.This issue affects Workreap Core: from n/a through <= 3.4.1.