Showing 3 vulnerabilities on this page for Real Estate 7 WordPress

Signals CISA KEV Ransomware Nuclei
contempoinc vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WP Pro Real Estate 7 <= 3.5.4 - Authenticated (Custom) Arbitrary File Upload

The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with Seller-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible if front-end listing submission has been enabled.

CWE-434Apr 1, 2025
CVSS8.8v3.1EPSS0.676%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administrator

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.

CWE-266Feb 12, 2025
CVSS9.8v3.1EPSS0.747%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

WordPress Real Estate 7 Theme <= 3.3.1 is vulnerable to Cross Site Scripting (XSS)

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions.

CWE-79Mar 27, 2023
CVSS7.1v3.1EPSS0.382%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX