PT-2025-27590 · WordPress · The Home Villas | Real Estate Wordpress Theme

Thái An

·

Published

2025-07-02

·

Updated

2025-07-07

·

CVE-2025-5014

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: The Home Villas | Real Estate WordPress Theme versions up to, and including, 2.8
Description: The issue is related to insufficient file path validation in the wp rem cs widget file delete function, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary files on the server. This can lead to remote code execution when specific files, such as wp-config.php, are deleted.
Recommendations: For versions up to, and including, 2.8, consider disabling the wp rem cs widget file delete function until a patch is available to prevent arbitrary file deletion. Restrict access to sensitive files on the server to minimize the risk of exploitation.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-5014

Affected Products

The Home Villas | Real Estate Wordpress Theme