Realia [realia] <= 1.4.0 (unfixed)
unknown
[en] The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the 'process_change_profile_form' function. This makes it possible for unauthenticated attackers to change user email via a forged request granted they can...
- Affected:
- up to 1.4.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 10, 2023
CVE-2023-4277 on NVD →
Realia <= 1.4.0 - Cross-Site Request Forgery to User Email Change
high
The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the 'process_change_profile_form' function. This makes it possible for unauthenticated attackers to change user email via a forged request granted they can tric...
- CVSS:
- 8.8
- Affected:
- up to 1.4.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 9, 2023
CVE-2023-4277 on NVD →
Realia <= 1.4.0 - Arbitrary Post Deletion
critical
The Realia plugin for WordPress is vulnerable to Arbitrary Post Deletion in versions up to, and including, 1.4.0. This is due to the 'includes/class-realia-submission.php' file. This makes it possible for unauthenticated attackers to delete any post within the vulnerability's scope.
- CVSS:
- 9.1
- Affected:
- up to 1.4.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 15, 2020
Realia [realia] <= 1.4.0 (unfixed + closed)
unknown
The Realia plugin for WordPress is vulnerable to Arbitrary Post Deletion in versions up to, and including, 1.4.0. This is due to the 'includes/class-realia-submission.php' file. This makes it possible for unauthenticated attackers to delete any post within the vulnerability's scope.
- Affected:
- up to 1.4.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 15, 2020
Realia [realia] < 1.5 (unfixed + closed)
unknown
Unauthenticated IDOR leading to Arbitrary Post Deletion vulnerability found by Vlad Vector, Erwan LR in WordPress Realia plugin (versions <= 1.4).
- Affected:
- up to 1.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 15, 2020
Realia <= 0.9.1 - Reflected Cross-Site Scripting
medium
The Realia plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 0.9.2 via the 'filter-id' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 0.9.2
- Fixed in:
- 0.9.2
- Disclosed:
- Mar 6, 2016
Realia [realia] < 0.9.2
unknown
The Realia plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 0.9.2 via the 'filter-id' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 0.9.2
- Fixed in:
- 0.9.2
- Disclosed:
- Mar 6, 2016
Realia [realia] <= 1.4 (unfixed + closed)
unknown
While investigating an IDOR issue on a premium theme, allowing arbitrary deletion of Ads, submitted by Vlad Vector, the Realia plugin was found to be the root cause.
In fact, having this plugin installed (which some themes require) can allow unauthenticated attackers to delete arbitrary posts, by submitting a malici...
- Affected:
- up to 1.4
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database