Beta

Report

Real Estate 7 <= 3.5.0 is vulnerable to Unauthenticated Privilege Escalation to Administrator vulnerability

Unauthenticated
Published
2025-02-10

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.

CVSS

Score:9.8

Severity:Critical

Version: 3.5.0

There is a patch available in v3.5.1 and we strongly recommend you update to this version as soon as possible.