Unknown Essential Real Estate vulnerabilities

4 known vulnerabilities affecting unknown/essential_real_estate.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-6140HIGHCVSS 8.8fixed in 4.4.02024-01-08
CVE-2023-6140 [HIGH] CWE-434 Essential Real Estate < 4.4 - Subscriber+ Arbitrary File Upload Essential Real Estate < 4.4 - Subscriber+ Arbitrary File Upload The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.
cvelistv5
CVE-2023-6139MEDIUMCVSS 6.5fixed in 4.4.02024-01-08
CVE-2023-6139 [MEDIUM] CWE-862 CVE-2023-6139: The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on i The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.
cvelistv5nvd
CVE-2023-6141MEDIUMCVSS 5.4fixed in 4.4.02024-01-08
CVE-2023-6141 [MEDIUM] CWE-79 CVE-2023-6141: The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on i The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.
cvelistv5nvd
CVE-2022-3933MEDIUMCVSS 5.4PoCfixed in 3.9.62022-12-12
CVE-2022-3933 [MEDIUM] CWE-79 CVE-2022-3933: The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameter The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.
cvelistv5nvd