The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.
References
Configurations
History
25 Feb 2025, 04:00
Type | Values Removed | Values Added |
---|---|---|
References | () https://contempothemes.com/changelog/ - Release Notes | |
References | () https://themeforest.net/item/wp-pro-real-estate-7-responsive-real-estate-wordpress-theme/12473778 - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/a50b3304-d55b-487a-8137-d5083c704cf4?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:contempothemes:real_estate_7:*:*:*:*:*:wordpress:*:* | |
CWE | NVD-CWE-noinfo | |
First Time |
Contempothemes real Estate 7
Contempothemes |
|
Summary |
|
12 Feb 2025, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-12 05:15
Updated : 2025-02-25 04:00
NVD link : CVE-2024-13421
Mitre link : CVE-2024-13421
CVE.ORG link : CVE-2024-13421
JSON object : View
Products Affected
contempothemes
- real_estate_7
CWE