PT-2026-4046 · WordPress · Real Homes Crm

Published

2026-01-22

·

Updated

2026-05-02

·

CVE-2025-67968

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Real Homes CRM versions prior to 1.0.1
Description The Real Homes CRM plugin bundled with the RealHomes WordPress theme contains a flaw that allows attackers to exploit weak authorization logic. This could lead to manipulation of user accounts and potential escalation of privileges, potentially resulting in full site takeover. Approximately 30,000 websites are estimated to be affected. The issue involves the unrestricted upload of files with dangerous types, allowing the use of malicious files. The vulnerability is related to the realhomes-crm component.
Recommendations Update Real Homes CRM to version 1.0.1 or later. Audit for suspicious admin creation, role changes, and unexpected CRM-related requests.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-67968

Affected Products

Real Homes Crm