VYPR

Real Estate Manager

by Webcodingplace

CVEs (2)

  • CVE-2023-4239HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.00

    The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.

  • CVE-2009-4318Dec 14, 2009
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information.