It Security

Critical zero-days impact premium WordPress real estate plugins

Teilen:

The RealHome theme and the Easy Real Estate plugins for WordPress are vulnerable to two critical severity flaws that allow unauthenticated users to gain administrative privileges.

Although the two flaws were discovered in September 2024 by Patchstack, and multiple attempts were made to contact the vendor (InspiryThemes), the researchers say they have not received a response.

Also, Patchstack says the vendor released three versions since September, but no security fixes to address the critical issues were introduced. Hence, the issues remain unfixed and exploitable.

Vulnerability details

The RealHome theme and Easy Real Estate are among the most popular themes and plugins designed for use in real estate websites. According to Envanto Market data, the RealHome theme is used in 32,600 websites.

The first flaw, which impacts RealHome theme, is an unauthenticated privilege escalation problem tracked as CVE-2024-32444 (CVSS score: 9.8).

The theme allows users to register new accounts via the inspiry_ajax_register function, however, it does not properly check authorization or implement a nonce validation.

If registration is enabled on the website, attackers can arbitrarily specify their role as “Administrator” in a specially crafted HTTP request to the registration function, essentially bypassing security checks.

Once registered as an administrator, the attacker can subsequently gain full control of the WordPress site, including performing content manipulation, planting scripts, and accessing user or other sensitive data.

The flaw impacting the Easy Real Estate plugin is another unauthenticated privilege escalation issue via the social login. It’s tracked under CVE-2024-32555 (CVSS score: 9.8).

The problem stems from the social login feature, which allows users to log in using their email address without verifying if it belongs to the person making the request.

As a result, if an attacker knows an admin’s email address, they can log in without needing a password. The repercussions of successful exploitation are similar to those of CVE-2024-32444.

Mitigation recommendations

As no patch has been released yet by InspiryThemes, website owners and administrators using the said theme or plugin should disable them immediately.

Restricting user registration on affected websites would also prevent unauthorized account creations, limiting the potential for exploitation.

As the problems on the two add-ons are now public, threat actors are bound to explore their potential and scan for vulnerable websites, so responding quickly to mitigate the threat is crucial at this point.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:08 pm, Juli 1, 2025
Wetter-Symbol 25°C
L: 24° | H: 27°
wenige Wolken
Luftfeuchtigkeit: 64 %
Druck: 1014 mb
Wind: 7 mph NE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 21%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:47 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
24° | 27°°C 0.38 mm 38% 11 mph 80 % 1022 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 13 mph 55 % 1028 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 12 mph 57 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
15° | 25°°C 1 mm 100% 15 mph 89 % 1022 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
14° | 19°°C 1 mm 100% 13 mph 81 % 1012 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 24°°C 0 mm 0% 5 mph 66 % 1014 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 20°°C 0 mm 0% 6 mph 74 % 1015 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0.2 mm 20% 5 mph 80 % 1017 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
21° | 21°°C 0.2 mm 20% 6 mph 71 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
19° | 19°°C 0.38 mm 38% 4 mph 69 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
23° | 23°°C 0.35 mm 35% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
23° | 23°°C 0.01 mm 1% 11 mph 28 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 34 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,651.75
-1.48%
Ethereum(ETH)
€2,044.24
-3.49%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.84
-5.02%
Solana(SOL)
€124.00
-6.33%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.134165
-5.00%
Shiba Inu(SHIB)
€0.000009
-3.09%
Pepe(PEPE)
€0.000008
-6.23%
Nach oben scrollen