Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows PHP Local File Inclusion.This issue affects Real Estate Manager: from n/a through <= 7.3.
Published: 2025-04-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper control of the filename used in a PHP include/require statement. This flaw allows an attacker to supply a crafted path that can result in Local File Inclusion. Such inclusion can expose sensitive files on the web server and may enable the upload or execution of malicious scripts, thereby compromising the confidentiality and integrity of the WordPress site. The weakness is identified as CWE‑98 and is classified as a moderate‑to‑high severity issue due to its potential effects on the entire WordPress installation.

Affected Systems

The affected product is the WordPress Real Estate Manager plugin developed by Rameez Iqbal. All releases from the earliest available version up through version 7.3 contain the flaw; patching or upgrading beyond 7.3 is required to remove the vulnerability.

Risk and Exploitability

The CVSS score of 7.5 indicates a high overall risk, while the EPSS score of less than 1% shows that exploitation is currently considered rare. The flaw is not listed in the CISA KEV catalog, so no known exploited instances are reported. The likely attack vector is remote; an adversary can trigger the vulnerability by accessing a URL or form that passes a malicious file path to the plugin. Successful exploitation would give the attacker read access to server files or the ability to upload and run code, potentially leading to full server compromise.

Generated by OpenCVE AI on May 1, 2026 at 00:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Real Estate Manager to a version newer than 7.3 where the LFI issue is fixed.
  • If an update is not available, disable or remove the plugin from the WordPress installation to eliminate the attack surface.
  • Implement server‑side path validation for any remaining include/require calls in the plugin code, restricting them to a whitelist of trusted files and blocking user‑supplied paths.

Generated by OpenCVE AI on May 1, 2026 at 00:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9870 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows PHP Local File Inclusion.This issue affects Real Estate Manager: from n/a through <= 7.3.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 04 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3.
Title WordPress Real Estate Manager plugin <= 7.3 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:17.463Z

Reserved: 2025-04-04T10:00:50.063Z

Link: CVE-2025-32150

cve-icon Vulnrichment

Updated: 2025-04-04T19:53:38.429Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:23.213

Modified: 2026-04-23T15:28:39.057

Link: CVE-2025-32150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T00:45:05Z

Weaknesses