Description
Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Password Brute Forcing.This issue affects Real Estate Manager: from n/a through <= 7.3.
Published: 2025-02-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Restriction of Excessive Authentication Attempts in the Rameez Iqbal Real Estate Manager plugin allows an attacker to try an unlimited number of passwords for a given account. Because the plugin does not enforce any lockout or rate‑limiting policy, a brute‑force attack can be conducted remotely through the login interface, potentially compromising user accounts and granting an attacker full control over the WordPress site. This weakness is identified as CWE‑307, which focuses on weak password policies or insufficient authentication controls.

Affected Systems

All installations of the WordPress Real Estate Manager plugin version 7.3 and earlier, including any earlier releases that share the same code base, are vulnerable. The vendor, Rameez Iqbal, produced the plugin in question. Even versions with no explicit version number are included because the issue affects the entire range up to and including 7.3.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Attackers can exploit this flaw by sending repeated login requests from any remote location that can reach the site's authentication endpoint, provided that network access to the administration area is available. The absence of a lockout feature means the attacker can continue attempts until the password is guessed.

Generated by OpenCVE AI on May 1, 2026 at 16:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest version of the Real Estate Manager plugin (7.4 or later) to eliminate the authentication‑bypass flaw.
  • Configure the website or the plugin to enforce a limit on authentication attempts or enable CAPTCHA to reduce the feasibility of brute‑force attacks.
  • Regularly review login logs and employ an account‑lockout policy or additional authentication factors to detect and block repeated failed attempts.

Generated by OpenCVE AI on May 1, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4781 Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager allows Password Brute Forcing. This issue affects Real Estate Manager: from n/a through 7.3.
History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager allows Password Brute Forcing. This issue affects Real Estate Manager: from n/a through 7.3. Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Password Brute Forcing.This issue affects Real Estate Manager: from n/a through <= 7.3.
Title WordPress Real Estate Manager – Property Listing and Agent Management plugin <= 7.3 - Captcha Bypass Vulnerability vulnerability WordPress Real Estate Manager plugin <= 7.3 - Captcha Bypass Vulnerability vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Tue, 18 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Feb 2025 20:00:00 +0000

Type Values Removed Values Added
Description Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager allows Password Brute Forcing. This issue affects Real Estate Manager: from n/a through 7.3.
Title WordPress Real Estate Manager – Property Listing and Agent Management plugin <= 7.3 - Captcha Bypass Vulnerability vulnerability
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:53.718Z

Reserved: 2025-01-07T21:02:36.083Z

Link: CVE-2025-22645

cve-icon Vulnrichment

Updated: 2025-02-18T20:14:14.088Z

cve-icon NVD

Status : Deferred

Published: 2025-02-18T20:15:26.570

Modified: 2026-04-29T10:16:39.460

Link: CVE-2025-22645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T16:15:20Z

Weaknesses