CVE-2026-39759: WordPress Workreap Core plugin <= 3.4.5 - Arbitrary File Upload vulnerability
Published Oct 6, 2026
·Updated
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
Affected Software
1 affected component
Amentotech Workreap Core<=3.4.5
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which accounts are exposed to this issue?
The affected upload functionality is associated with Employer and Sales Representative roles. Exploitation requires an attacker to have low-privileged access, as reflected by the PR:L vector.
2
Can this be exploited remotely without user interaction?
Yes. The vector indicates network-based exploitation with low attack complexity and no user interaction required, but the attacker must first have the required low-level privileges.
3
What versions are known to be affected?
Workreap Core versions through 3.4.5 are identified as affected. The provided data does not specify a fixed version.