Impact
The vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels. This flaw lets an attacker act with higher privileges than intended, enabling them to perform functions meant for administrators or privileged users. The weakness corresponds to CWE‑862.
Affected Systems
The flaw affects the g5theme Essential Real Estate WordPress plugin, versions up to and including 5.3.2. Any WordPress site that has this plugin installed and not updated is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while an EPSS score below 1 % suggests exploitation is unlikely and it is not listed in the CISA KEV catalog. Attackers are expected to target the plugin over the web, likely by authenticating with a lower‑privilege account or exploiting a publicly accessible endpoint, and then exercising the elevated privileges that the missing access control permits.
OpenCVE Enrichment