CVE-2025-4601
HIGHRH - Real Estate WordPress Theme <4.4.0 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-4601. PoCs published by Yucaerin.
AI-analyzed exploit summary This repository provides a detailed writeup for CVE-2025-4601, a privilege escalation vulnerability in the WordPress RealHomes theme <= 4.4.0. It explains how authenticated users with low privileges can escalate their role to administrator via a crafted POST request to the `admin-ajax.php` endpoint.
Description
The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to the theme not properly restricting user roles that can be updated as part of the inspiry_update_profile() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to set their role to that of an administrator. The vulnerability was partially patched in version 4.4.0, and fully patched in version 4.4.1.
Exploits (1)
This repository provides a detailed writeup for CVE-2025-4601, a privilege escalation vulnerability in the WordPress RealHomes theme <= 4.4.0. It explains how authenticated users with low privileges can escalate their role to administrator via a crafted POST request to the `admin-ajax.php` endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H