contempoinc Vulnerabilities and Affected Products
Vulnerabilities associated with Real Estate 7 WordPress.
Products
Clear product- Real Estate 74 vulnerabilities
- Real Estate 7 WordPress3 vulnerabilities
- Contempo Real Estate Core1 vulnerability
- WP Pro Real Estate 71 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-2891HIGH | WP Pro Real Estate 7 <= 3.5.4 - Authenticated (Custom) Arbitrary File UploadThe Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with Seller-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible if front-end listing submission has been enabled. CWE-434Apr 1, 2025 | CVSS8.8v3.1 | EPSS0.676% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-13421CRITICAL | Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to AdministratorThe Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account. CWE-266Feb 12, 2025 | CVSS9.8v3.1 | EPSS0.747% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-47146HIGH | WordPress Real Estate 7 Theme <= 3.3.1 is vulnerable to Cross Site Scripting (XSS)Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions. CWE-79Mar 27, 2023 | CVSS7.1v3.1 | EPSS0.382% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |