Description
Cross-Site Request Forgery (CSRF) vulnerability in WpEstate WP Rentals wprentals allows Cross Site Request Forgery.This issue affects WP Rentals: from n/a through <= 3.13.1.
Published: 2025-10-29
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery (CSRF) flaw that allows an attacker to trick a user into submitting a forged request to the WordPress WP Rentals theme. The flaw can be abused to trigger state‑changing actions on the site, potentially altering data or performing unauthorized operations. The weakness is identified as CWE‑352. The impact is limited to the permissions of the victim user but can affect the confidentiality, integrity, or availability of the rental listings and associated data.

Affected Systems

WpEstate’s WP Rentals WordPress theme, versions up through 3.13.1, is affected. Site administrators running these versions should verify whether their installations include the theme. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity vulnerability. The EPSS score of less than 1% reflects a low probability of exploitation. This issue is not listed in the CISA KEV catalog, so no known active exploitation patches are reported. An attacker would need to present a crafted request to a user who is currently authenticated to the site. Based on the description, the likely attack vector is a malicious external page that forces an authenticated user to send a request to the theme’s endpoints without proper CSRF protection.

Generated by OpenCVE AI on April 29, 2026 at 20:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Rentals theme to the latest version (≥ 3.14) where the CSRF issue is resolved.
  • If an update is not immediately possible, implement a CSRF token check on all sensitive endpoints of the theme, ensuring that only requests containing a valid nonce are processed.
  • Enforce stricter user role limitations or disable features that perform state changes for users with low privileges, reducing the potential impact of a forged request.

Generated by OpenCVE AI on April 29, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpestate
Wpestate wp Rentals
Vendors & Products Wordpress
Wordpress wordpress
Wpestate
Wpestate wp Rentals

Wed, 29 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 09:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WpEstate WP Rentals wprentals allows Cross Site Request Forgery.This issue affects WP Rentals: from n/a through <= 3.13.1.
Title WordPress WP Rentals theme <= 3.13.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Wordpress Wordpress
Wpestate Wp Rentals
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:13.350Z

Reserved: 2025-10-29T03:29:08.850Z

Link: CVE-2025-64286

cve-icon Vulnrichment

Updated: 2025-10-29T14:04:20.322Z

cve-icon NVD

Status : Deferred

Published: 2025-10-29T09:15:46.097

Modified: 2026-04-27T16:16:39.917

Link: CVE-2025-64286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:30:19Z

Weaknesses