Extension WordPress

Vulnérabilités Real Estate Manager – Property Listing and Agent Management

Cette page rassemble les failles publiées pour Real Estate Manager – Property Listing and Agent Management, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
2Critiques
1Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Real Estate Manager – Property Listing and Agent Management

9 fiches

CVE-2025-58253 Moyenne · 6,4
Real Estate Manager – Property Listing and Agent Management

Real Estate Manager <= 7.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Real Estate Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-7.3

Correctif

Non indiqué

Publication

22/09/2025

CVE-2025-32596 Critique · 9,8
Real Estate Manager – Property Listing and Agent Management

Real Estate Manager <= 7.3 – Unauthenticated Remote Code Execution

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to execute code on…

Versions affectées

*-7.3

Correctif

Non indiqué

Publication

15/04/2025

CVE-2025-32668 Critique · 9,8
Real Estate Manager – Property Listing and Agent Management

Real Estate Manager <= 7.3 – Unauthenticated Local File Inclusion

The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the…

Versions affectées

*-7.3

Correctif

Non indiqué

Publication

09/04/2025

CVE-2025-32150 Élevée · 8,8
Real Estate Manager – Property Listing and Agent Management

Real Estate Manager <= 7.3 – Authenticated (Contributor+) Local File Inclusion

The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files…

Versions affectées

*-7.3

Correctif

Non indiqué

Publication

04/04/2025

CVE-2025-22645 Moyenne · 5,3
Real Estate Manager – Property Listing and Agent Management

Real Estate Manager – Property Listing and Agent Management <= 7.3 – CAPTCHA Bypass

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to CAPTCHA Bypass in all versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to bypass CAPTCHA.

Versions affectées

*-7.3

Correctif

Non indiqué

Publication

03/02/2025

CVE-2023-4239 Élevée · 8,8
Real Estate Manager – Property Listing and Agent Management

Real Estate Manager <= 7.2 – Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation

The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such…

Versions affectées

*-7.2

Correctif

Non indiqué

Publication

08/08/2023

Vulnérabilité Moyenne · 6,1
Real Estate Manager – Property Listing and Agent Management

Real Estate Manager – Property Listing and Agent Management <= 6.8 – Cross-Site Scripting

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘revision’ parameter in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping.…

Versions affectées

*-6.8

Correctif

7.0

Publication

13/06/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités