Real Estate Manager <= 7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Real Estate Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Sep 22, 2025
CVE-2025-58253 on NVD →
Real Estate Manager – Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager allows Cross Site Request Forgery. This issue affects Real Estate Manager: from n/a through 7.3.
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2025
CVE-2025-50044 on NVD →
Real Estate Manager – Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager allows Privilege Escalation. This issue affects Real Estate Manager: from n/a through 7.3.
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2025
CVE-2025-52825 on NVD →
Real Estate Manager <= 7.3 - Cross-Site Request Forgery
medium
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized...
- CVSS:
- 4.3
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2025
CVE-2025-52825 on NVD →
Real Estate Manager <= 7.3 - Cross-Site Request Forgery
medium
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized...
- CVSS:
- 4.3
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2025
CVE-2025-50044 on NVD →
Real Estate Manager – Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Rameez Iqbal Real Estate Manager allows Code Injection. This issue affects Real Estate Manager: from n/a through 7.3.
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2025-32596 on NVD →
Real Estate Manager <= 7.3 - Unauthenticated Remote Code Execution
critical
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 15, 2025
CVE-2025-32596 on NVD →
Real Estate Manager – Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3.
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 10, 2025
CVE-2025-32668 on NVD →
Real Estate Manager <= 7.3 - Unauthenticated Local File Inclusion
critical
The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access co...
- CVSS:
- 9.8
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2025
CVE-2025-32668 on NVD →
Real Estate Manager <= 7.3 - Authenticated (Contributor+) Local File Inclusion
high
The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those fil...
- CVSS:
- 8.8
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32150 on NVD →
Real Estate Manager – Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3.
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32150 on NVD →
Real Estate Manager – Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)
unknown
[en] Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager allows Password Brute Forcing. This issue affects Real Estate Manager: from n/a through 7.3.
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 18, 2025
CVE-2025-22645 on NVD →
Real Estate Manager – Property Listing and Agent Management <= 7.3 - CAPTCHA Bypass
medium
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to CAPTCHA Bypass in all versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to bypass CAPTCHA.
- CVSS:
- 5.3
- Affected:
- up to 7.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2025
CVE-2025-22645 on NVD →
Real Estate Manager <= 7.2 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
high
The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role...
- CVSS:
- 8.8
- Affected:
- up to 7.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 8, 2023
CVE-2023-4239 on NVD →
Real Estate Manager – Property Listing and Agent Management <= 6.8 - Cross-Site Scripting
medium
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘revision’ parameter in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...
- CVSS:
- 6.1
- Affected:
- up to 6.8
- Fixed in:
- 7.0
- Disclosed:
- Jun 13, 2019
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database