Impact
The vulnerability is an unauthenticated CSRF in WordPress Real Estate 7 Theme versions 3.5.9 and earlier. It permits an attacker to forge requests performed by an authenticated user, potentially allowing the attacker to modify site settings, postings, or other theme‑driven actions. The flaw is a classic CWE‑352 condition that threatens the integrity of the site and may impact availability when the site is overloaded by forged requests.
Affected Systems
All WordPress sites that employ the Contempoinc Real Estate 7 theme version 3.5.9 or older are affected, regardless of the web server or hosting environment.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is not available, so exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA KEV. Because the vector is web‑based and unauthenticated, the attack can be performed remotely from a browser, especially if the victim is logged in and has elevated privileges.
OpenCVE Enrichment