Real Estate 7
by WordPress
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-13421 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2025 | The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated… | ||
| CVE-2025-2891 | Hig | 0.57 | 8.8 | 0.01 | Apr 1, 2025 | The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with… | ||
| CVE-2025-39459 | Hig | 0.47 | 7.3 | 0.00 | May 19, 2025 | Incorrect Privilege Assignment vulnerability in contempoinc Real Estate 7 realestate-7 allows Privilege Escalation.This issue affects Real Estate 7: from n/a through <= 3.5.2. | ||
| CVE-2022-47146 | Hig | 0.46 | 7.1 | 0.00 | Mar 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions. | ||
| CVE-2026-57343 | Hig | 0.00 | 7.1 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions. | ||
| CVE-2026-57641 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions. | ||
| CVE-2026-54827 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. |
- risk 0.64cvss 9.8epss 0.01
The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated…
- risk 0.57cvss 8.8epss 0.01
The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with…
- risk 0.47cvss 7.3epss 0.00
Incorrect Privilege Assignment vulnerability in contempoinc Real Estate 7 realestate-7 allows Privilege Escalation.This issue affects Real Estate 7: from n/a through <= 3.5.2.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.