plugin

Real Estate Manager Vulnerabilities

15 known security issues reported for the Real Estate Manager WordPress plugin. Most recent disclosed Sep 22, 2025.

2 critical 2 high 5 medium

Running Real Estate Manager on your site? Check whether your installed version is affected.

Scan your site free

Real Estate Manager <= 7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Real Estate Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Sep 22, 2025

CVE-2025-58253 on NVD →

Real Estate Manager &#8211; Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager allows Cross Site Request Forgery. This issue affects Real Estate Manager: from n/a through 7.3.

Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-50044 on NVD →

Real Estate Manager &#8211; Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager allows Privilege Escalation. This issue affects Real Estate Manager: from n/a through 7.3.

Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-52825 on NVD →

Real Estate Manager <= 7.3 - Cross-Site Request Forgery

medium

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized...

CVSS:
4.3
Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Jun 19, 2025

CVE-2025-52825 on NVD →

Real Estate Manager <= 7.3 - Cross-Site Request Forgery

medium

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized...

CVSS:
4.3
Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Jun 19, 2025

CVE-2025-50044 on NVD →

Real Estate Manager &#8211; Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Rameez Iqbal Real Estate Manager allows Code Injection. This issue affects Real Estate Manager: from n/a through 7.3.

Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-32596 on NVD →

Real Estate Manager <= 7.3 - Unauthenticated Remote Code Execution

critical

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Apr 15, 2025

CVE-2025-32596 on NVD →

Real Estate Manager &#8211; Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3.

Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Apr 10, 2025

CVE-2025-32668 on NVD →

Real Estate Manager <= 7.3 - Unauthenticated Local File Inclusion

critical

The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access co...

CVSS:
9.8
Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Apr 9, 2025

CVE-2025-32668 on NVD →

Real Estate Manager <= 7.3 - Authenticated (Contributor+) Local File Inclusion

high

The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those fil...

CVSS:
8.8
Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32150 on NVD →

Real Estate Manager &#8211; Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3.

Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32150 on NVD →

Real Estate Manager &#8211; Property Listing and Agent Management [real-estate-manager] <= 7.3 (unfixed)

unknown

[en] Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager allows Password Brute Forcing. This issue affects Real Estate Manager: from n/a through 7.3.

Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Feb 18, 2025

CVE-2025-22645 on NVD →

Real Estate Manager – Property Listing and Agent Management <= 7.3 - CAPTCHA Bypass

medium

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to CAPTCHA Bypass in all versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to bypass CAPTCHA.

CVSS:
5.3
Affected:
up to 7.3
Fix:
No patched version reported
Disclosed:
Feb 3, 2025

CVE-2025-22645 on NVD →

Real Estate Manager <= 7.2 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation

high

The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role...

CVSS:
8.8
Affected:
up to 7.2
Fix:
No patched version reported
Disclosed:
Aug 8, 2023

CVE-2023-4239 on NVD →

Real Estate Manager – Property Listing and Agent Management <= 6.8 - Cross-Site Scripting

medium

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘revision’ parameter in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...

CVSS:
6.1
Affected:
up to 6.8
Fixed in:
7.0
Disclosed:
Jun 13, 2019

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database