Impact
The WP Real Estate Manager plugin suffers an authentication bypass due to insufficient identity verification on the LinkedIn login request process. This flaw enables attackers who are not authenticated to act as any user on the site, including administrators. Consequently, an attacker could gain full control over the WordPress site, modify listings, change settings, or extract sensitive data.
Affected Systems
All versions of the Chimpstudio WP Real Estate Manager plugin up to and including 2.8 are affected. The vulnerability applies to any WordPress installation that has the plugin installed and the LinkedIn login feature enabled.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating critical severity. The EPSS score is below 1%, suggesting that, while high impact, the likelihood of exploitation is currently low to moderate. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to exploit the LinkedIn authentication flow, which is possible when the plugin's LinkedIn integration is active; the flaw does not require additional access permissions.
OpenCVE Enrichment
EUVD