The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api_key and save_api_key AJAX actions in all versions up to, and including, 3.6. This makes it possible for unauthenticated attackers to issue requests to internal services and update API key details.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 14 Mar 2025 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api_key and save_api_key AJAX actions in all versions up to, and including, 3.6. This makes it possible for unauthenticated attackers to issue requests to internal services and update API key details. | |
Title | Resido - Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side Request Forgery and API Key Settings Update | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-14T04:22:32.126Z
Updated: 2025-03-14T15:13:58.496Z
Reserved: 2025-02-13T17:58:40.682Z
Link: CVE-2025-1285

Updated: 2025-03-14T15:13:45.539Z

Status : Received
Published: 2025-03-14T05:15:41.977
Modified: 2025-03-14T05:15:41.977
Link: CVE-2025-1285

No data.