Description
Cross-Site Request Forgery (CSRF) vulnerability in ReichertBrothers SimplyRETS Real Estate IDX simply-rets allows Cross Site Request Forgery.This issue affects SimplyRETS Real Estate IDX: from n/a through <= 3.0.5.
Published: 2025-03-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw in the SimplyRETS Real Estate IDX plugin that allows an attacker to execute a range of administrative actions without the victim’s knowledge. The flaw can be exploited by tricking an authenticated administrator into visiting a malicious webpage that submits unintended requests to the plugin. The weakness is classified as CWE‑352, highlighting the absence of proper anti‑CSRF controls during form submission or processing. The attack vector is not explicitly stated in the description; it is inferred that an attacker would need to lure an admin to a malicious site that triggers forged requests. Also, the requirement for user interaction and authenticated admin access is inferred from the description of the vulnerability, as it is essential for CSRF exploitation.

Affected Systems

The affected product is the ReichertBrothers SimplyRETS Real Estate IDX WordPress plugin, specifically all versions up to and including 3.0.5. Users running these plugin versions should identify their installation and verify whether it is still in use.

Risk and Exploitability

The CVSS score of 4.3 classifies the vulnerability as moderate, reflecting that it requires user interaction and administrator credentials to be useful. The EPSS score of less than 1% indicates that exploitation is unlikely in the general population, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation would typically occur when an authenticated admin visits a crafted malicious site, which can then inject form submissions or AJAX requests triggering privileged actions within the plugin. Because the attack depends on social engineering or malicious HTML, defenders should monitor for anomalous requests targeting admin endpoints and reduce the attack surface by ensuring CSRF protections are in place. The requirement for user interaction and the need for administrator credentials are not directly described but are inferred based on the nature of CSRF flaws and the described impact.

Generated by OpenCVE AI on May 2, 2026 at 02:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SimplyRETS Real Estate IDX plugin to the latest version that contains a CSRF mitigation fix.
  • Verify that the plugin’s administrative interfaces include anti‑CSRF tokens and that submitted tokens are validated correctly.
  • Configure a Web Application Firewall or security plugin to flag or block unauthorized POST requests to admin endpoints and to enforce re‑authentication for sensitive actions.

Generated by OpenCVE AI on May 2, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14790 Cross-Site Request Forgery (CSRF) vulnerability in ReichertBrothers SimplyRETS Real Estate IDX allows Cross Site Request Forgery. This issue affects SimplyRETS Real Estate IDX: from n/a through 3.0.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in ReichertBrothers SimplyRETS Real Estate IDX allows Cross Site Request Forgery. This issue affects SimplyRETS Real Estate IDX: from n/a through 3.0.3. Cross-Site Request Forgery (CSRF) vulnerability in ReichertBrothers SimplyRETS Real Estate IDX simply-rets allows Cross Site Request Forgery.This issue affects SimplyRETS Real Estate IDX: from n/a through <= 3.0.5.
Title WordPress SimplyRETS Real Estate IDX plugin <= 3.0.3 - CSRF to Multiple Admin Actions vulnerability WordPress SimplyRETS Real Estate IDX plugin <= 3.0.5 - CSRF to Multiple Admin Actions vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Fri, 28 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in ReichertBrothers SimplyRETS Real Estate IDX allows Cross Site Request Forgery. This issue affects SimplyRETS Real Estate IDX: from n/a through 3.0.3.
Title WordPress SimplyRETS Real Estate IDX plugin <= 3.0.3 - CSRF to Multiple Admin Actions vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:03.607Z

Reserved: 2025-03-26T09:22:56.081Z

Link: CVE-2025-31010

cve-icon Vulnrichment

Updated: 2025-03-28T15:51:59.463Z

cve-icon NVD

Status : Deferred

Published: 2025-03-28T15:15:51.367

Modified: 2026-04-23T15:27:31.600

Link: CVE-2025-31010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:00:13Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)