Логотип exploitDog
bind:CVE-2025-2237
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-2237

Количество 2

Количество 2

nvd логотип

CVE-2025-2237

5 месяцев назад

The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to authentication bypass in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an account with the Administrator role.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g49-fr8w-j923

5 месяцев назад

The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to authentication bypass in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an account with the Administrator role.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-2237

The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to authentication bypass in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an account with the Administrator role.

CVSS3: 9.8
1%
Низкий
5 месяцев назад
github логотип
GHSA-2g49-fr8w-j923

The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to authentication bypass in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an account with the Administrator role.

CVSS3: 9.8
1%
Низкий
5 месяцев назад

Уязвимостей на страницу