What the vulnerability does
01Description
Incorrect Privilege Assignment vulnerability in InspiryThemes Easy Real Estate easy-real-estate allows Privilege Escalation.This issue affects Easy Real Estate: from n/a through <= 2.2.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Incorrect Privilege Assignment vulnerability in InspiryThemes Easy Real Estate easy-real-estate allows Privilege Escalation.This issue affects Easy Real Estate: from n/a through <= 2.2.9.
Explanation of Vulnerability in Simple Terms
Easy Real Estate versions 2.2.9 and earlier contain a critical vulnerability that allows unauthenticated attackers to read sensitive data, modify site content, or disrupt service without any user interaction. The vulnerability stems from improper access control that fails to restrict unauthorized actions. All sites running affected versions require immediate patching.
What an attacker can do
Read sensitive data, modify or delete content, and disrupt site availability without authentication.
Potential impact on your site
Attackers can compromise your site's data, deface content, and cause downtime without any warning or user action.
Conditions required to exploit
Network access only; no authentication, user interaction, or special configuration required.
Key dates
External resources
Related vulnerabilities