Impact
The vulnerability is a missing authorization flaw in the Real Estate Pro plugin for WordPress. The improper configuration of access control levels allows an attacker to access functionality or data intended for higher‑privilege users. This can lead to unauthorized viewing or manipulation of real‑estate listings and related data, compromising confidentiality and integrity.
Affected Systems
The e‑plugins Real Estate Pro WordPress plugin, versions up to and including 2.1.5, is affected. Any site that has this plugin installed and has not upgraded beyond 2.1.5 must consider this vulnerability.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. The EPSS score is less than 1%, suggesting that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. Because the flaw stems from broken access control, attackers likely need to authenticate to the site or exploit an existing user session; however the lack of proper checks means that any authenticated user could potentially elevate privileges or access sensitive data, making the flaw exploitable via standard web requests.
OpenCVE Enrichment