PT-2026-4046 · WordPress · Real Homes Crm
Published
2026-01-22
·
Updated
2026-05-02
·
CVE-2025-67968
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Real Homes CRM versions prior to 1.0.1
Description
The Real Homes CRM plugin bundled with the RealHomes WordPress theme contains a flaw that allows attackers to exploit weak authorization logic. This could lead to manipulation of user accounts and potential escalation of privileges, potentially resulting in full site takeover. Approximately 30,000 websites are estimated to be affected. The issue involves the unrestricted upload of files with dangerous types, allowing the use of malicious files. The vulnerability is related to the
realhomes-crm component.Recommendations
Update Real Homes CRM to version 1.0.1 or later.
Audit for suspicious admin creation, role changes, and unexpected CRM-related requests.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Real Homes Crm