The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Contempothemes
Contempothemes real Estate 7 |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:contempothemes:real_estate_7:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Contempothemes
Contempothemes real Estate 7 |
Wed, 12 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 12 Feb 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account. | |
Title | Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administrator | |
Weaknesses | CWE-266 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-12T04:22:15.326Z
Updated: 2025-02-12T16:09:23.340Z
Reserved: 2025-01-15T18:49:58.633Z
Link: CVE-2024-13421

Updated: 2025-02-12T16:00:56.479Z

Status : Analyzed
Published: 2025-02-12T05:15:11.653
Modified: 2025-02-25T04:00:16.123
Link: CVE-2024-13421

No data.