contempothemes.com
https://contempothemes.com/changelog CVE-2024-13421
CRITICAL
Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administrator
Record summary
CVE-2024-13421 has a selected CVSS score of 9.8 (critical).
Description
The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 4, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 12, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Real Estate 7 WordPressBrowse contempoinc / Real Estate 7 WordPressDefault status: unaffected | CVE List | Through 3.5.1 | affected |
real_estate_7Browse contempothemes / real_estate_7 | VulnCheck | Version data not supplied | |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-13421 themeforest.net
https://themeforest.net/item/wp-pro-real-estate-7-responsive-real-estate-wordpress-theme/12473778 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/a50b3304-d55b-487a-8137-d5083c704cf4?source=cve