CVE-2025-4601

HIGH

RH - Real Estate WordPress Theme <4.4.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-4601. PoCs published by Yucaerin.

AI-analyzed exploit summary This repository provides a detailed writeup for CVE-2025-4601, a privilege escalation vulnerability in the WordPress RealHomes theme <= 4.4.0. It explains how authenticated users with low privileges can escalate their role to administrator via a crafted POST request to the `admin-ajax.php` endpoint.

Description

The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to the theme not properly restricting user roles that can be updated as part of the inspiry_update_profile() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to set their role to that of an administrator. The vulnerability was partially patched in version 4.4.0, and fully patched in version 4.4.1.

Exploits (1)

nomisec WRITEUP
by Yucaerin · poc
https://github.com/Yucaerin/CVE-2025-4601

This repository provides a detailed writeup for CVE-2025-4601, a privilege escalation vulnerability in the WordPress RealHomes theme <= 4.4.0. It explains how authenticated users with low privileges can escalate their role to administrator via a crafted POST request to the `admin-ajax.php` endpoint.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WordPress RealHomes Theme <= 4.4.0
Auth required
Prerequisites: Authenticated user with low privileges (e.g., subscriber) · The `ere_allow_users_change_role` option must be enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0417
EPSS Percentile 89.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
InspiryThemes/RH - Real Estate WordPress Theme < 4.4.0
Published Jun 10, 2025
Tracked Since Feb 18, 2026