PT-2025-47689 · WordPress · Realty Portal

Kenneth Dunn

·

Published

2025-11-21

·

Updated

2025-11-26

·

CVE-2025-11985

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Realty Portal plugin for WordPress versions 0.1 through 0.4.1
Description The Realty Portal plugin for WordPress is susceptible to unauthorized data modification, potentially leading to privilege escalation. A missing capability check within the rp save property settings function allows authenticated attackers with Subscriber-level access or higher to update arbitrary options on a WordPress site. This can be exploited to modify the default registration role to administrator and enable user registration, allowing attackers to gain administrative access.
Recommendations Update the Realty Portal plugin to a version newer than 0.4.1.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-11985

Affected Products

Realty Portal