VYPR

Real Estate 7

by WordPress

CVEs (7)

  • CVE-2024-13421CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated…

  • CVE-2025-2891HigApr 1, 2025
    risk 0.57cvss 8.8epss 0.01

    The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with…

  • CVE-2025-39459HigMay 19, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect Privilege Assignment vulnerability in contempoinc Real Estate 7 realestate-7 allows Privilege Escalation.This issue affects Real Estate 7: from n/a through <= 3.5.2.

  • CVE-2022-47146HigMar 27, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions.

  • CVE-2026-57343HigJul 2, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.

  • CVE-2026-57641MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.

  • CVE-2026-54827CriJun 26, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.