PT-2025-14092 · WordPress · Wp Realestate

Tonn

·

Published

2025-04-01

·

Updated

2025-04-05

·

CVE-2025-2237

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP RealEstate plugin versions up to, and including, 1.6.26
Description The issue is related to insufficient role restrictions in the process register function, allowing unauthenticated attackers to register an account with the Administrator role, effectively bypassing authentication and gaining admin access.
Recommendations For versions up to, and including, 1.6.26, update to a version later than 1.6.26 to resolve the issue. As a temporary workaround, consider disabling the process register function until a patch is available.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-2237

Affected Products

Wp Realestate