What the vulnerability does
01Description
The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.
Explanation of Vulnerability in Simple Terms
02Summary
The Real Estate 7 WordPress plugin versions 3.5.1 and earlier contain a critical vulnerability that allows unauthenticated attackers to read sensitive data, modify site content, and disrupt service. No special conditions are required to exploit this flaw. Site administrators should update immediately to a version newer than 3.5.1.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify content, and disrupt the site without needing to log in.
Potential impact on your site
04Site Impact
Your site's data can be stolen, altered, or deleted by anyone on the internet without a password.
Conditions required to exploit
05Prerequisites
None. The attacker can exploit this remotely over the network without authentication or user interaction.
Key dates
06Disclosure timeline
February 12, 2025
CVE published
April 8, 2026
Record updated