CVE-2022-3846: Workreap - Freelance Marketplace and Directory < 2.6.3 - Subscriber+ Private Message Disclosure via IDOR
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3846?
CVE-2022-3846 is considered a medium severity vulnerability due to the potential for unauthorized access to user notifications.
How do I fix CVE-2022-3846?
To fix CVE-2022-3846, upgrade the Workreap WordPress theme to version 2.6.3 or later.
What kind of notifications are affected by CVE-2022-3846?
CVE-2022-3846 affects both employer and freelancer notifications within the Workreap WordPress theme.
Can CVE-2022-3846 lead to sensitive information exposure?
Yes, CVE-2022-3846 can lead to unauthorized users being able to read other users' notifications, potentially exposing sensitive information.
Is the vulnerability CVE-2022-3846 present in earlier versions of Workreap?
Yes, CVE-2022-3846 is present in all versions of the Workreap WordPress theme prior to version 2.6.3.