SmartDataSoft Vulnerabilities and Affected Products
Vulnerabilities associated with Essential WP Real Estate.
Products
Clear product- DriCub2 vulnerabilities
- Essential WP Real Estate2 vulnerabilities
- SmartBlog2 vulnerabilities
- Car Repair Services1 vulnerability
- Clasifico Listing1 vulnerability
- Electrician - Electrical Service WordPress1 vulnerability
- Pool Services1 vulnerability
- Resido - Real Estate WordPress Theme1 vulnerability
- Reveal Listing1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-23857HIGH | WordPress Essential WP Real Estate Plugin <= 1.1.3 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SmartDataSoft Essential WP Real Estate essential-wp-real-estate allows Reflected XSS.This issue affects Essential WP Real Estate: from n/a through <= 1.1.3. CWE-79Feb 14, 2025 | CVSS7.1v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-13318MEDIUM | Essential WP Real Estate <= 1.1.3 - Missing Authorization to Arbitrary Post/Page DeletionThe Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts. CWE-463Jan 10, 2025 | CVSS5.3v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |