Description
Cross-Site Request Forgery (CSRF) vulnerability in g5theme Essential Real Estate essential-real-estate allows Cross Site Request Forgery.This issue affects Essential Real Estate: from n/a through <= 5.1.8.
Published: 2025-01-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Essential Real Estate plugin for WordPress contains a Cross‑Site Request Forgery flaw (CWE‑352) that permits an attacker to compel a victim’s browser to send authenticated requests to the site, enabling state‑changing actions such as modifying listings, altering settings, or otherwise tampering with data while the victim is logged in. This vulnerability does not allow direct code execution or data exfiltration; its impact lies in compromising data integrity and user trust through unauthorized actions performed on behalf of the user.

Affected Systems

All WordPress sites running the g5theme Essential Real Estate plugin version 5.1.8 or earlier are affected. The issue applies across all installations of the plugin that have not been updated beyond that version.

Risk and Exploitability

The flaw carries a CVSS score of 4.3, placing it in the medium severity range. An EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely a malicious web page that lures a logged‑in user to visit the site and trigger the vulnerable endpoint, exploiting the absence of a proper CSRF token or nonce. No additional technical prerequisites beyond user interaction are required, so the overall risk is governed mainly by the low exploitation probability.

Generated by OpenCVE AI on May 2, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the plugin’s official release notes or the vendor’s website for an updated version that addresses the CSRF flaw and upgrade if available.
  • Verify that all state‑changing actions in the plugin include a valid WordPress nonce or CSRF token and reject any requests that lack proper validation.
  • Restrict or disable plugin endpoints that are not essential, ensuring that only authenticated users with the necessary capabilities can access sensitive operations.

Generated by OpenCVE AI on May 2, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3890 Cross-Site Request Forgery (CSRF) vulnerability in G5Theme Essential Real Estate allows Cross Site Request Forgery. This issue affects Essential Real Estate: from n/a through 5.1.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in G5Theme Essential Real Estate allows Cross Site Request Forgery. This issue affects Essential Real Estate: from n/a through 5.1.8. Cross-Site Request Forgery (CSRF) vulnerability in g5theme Essential Real Estate essential-real-estate allows Cross Site Request Forgery.This issue affects Essential Real Estate: from n/a through <= 5.1.8.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 09 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared G5plus
G5plus essential Real Estate
CPEs cpe:2.3:a:g5plus:essential_real_estate:*:*:*:*:*:wordpress:*:*
Vendors & Products G5plus
G5plus essential Real Estate

Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in G5Theme Essential Real Estate allows Cross Site Request Forgery. This issue affects Essential Real Estate: from n/a through 5.1.8.
Title WordPress Essential Real Estate plugin <= 5.1.8 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

G5plus Essential Real Estate
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:32.102Z

Reserved: 2025-01-23T14:52:23.104Z

Link: CVE-2025-24698

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2025-01-24T18:15:43.050

Modified: 2026-06-17T08:59:27.633

Link: CVE-2025-24698

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:30:26Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)