Impact
A Cross‑Site Request Forgery flaw allows an attacker to force a logged‑in WordPress user to act on the site without the user’s consent. Because the Real Estate Manager plugin does not verify a CSRF token, malicious sites can submit form requests that create, modify, or delete real‑estate listings, potentially altering data integrity and exposing sensitive information.
Affected Systems
WordPress installations that use Rameez Iqbal’s Real Estate Manager plugin version 7.3 or earlier are affected. All releases from the first available version up to and including 7.3 contain the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% reflects an extremely low but non‑zero chance of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been widely abused. The attack vector is inferable as low‑intercept, requiring the victim to be authenticated to the site; the attacker can then submit forged requests from another origin.
OpenCVE Enrichment
EUVD