plugin

Realia Vulnerabilities

8 known security issues reported for the Realia WordPress plugin. Most recent disclosed Aug 10, 2023.

1 critical 1 high 1 medium

Running Realia on your site? Check whether your installed version is affected.

Scan your site free

Realia [realia] <= 1.4.0 (unfixed)

unknown

[en] The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the 'process_change_profile_form' function. This makes it possible for unauthenticated attackers to change user email via a forged request granted they can...

Affected:
up to 1.4.0
Fix:
No patched version reported
Disclosed:
Aug 10, 2023

CVE-2023-4277 on NVD →

Realia <= 1.4.0 - Cross-Site Request Forgery to User Email Change

high

The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the 'process_change_profile_form' function. This makes it possible for unauthenticated attackers to change user email via a forged request granted they can tric...

CVSS:
8.8
Affected:
up to 1.4.0
Fix:
No patched version reported
Disclosed:
Aug 9, 2023

CVE-2023-4277 on NVD →

Realia <= 1.4.0 - Arbitrary Post Deletion

critical

The Realia plugin for WordPress is vulnerable to Arbitrary Post Deletion in versions up to, and including, 1.4.0. This is due to the 'includes/class-realia-submission.php' file. This makes it possible for unauthenticated attackers to delete any post within the vulnerability's scope.

CVSS:
9.1
Affected:
up to 1.4.0
Fix:
No patched version reported
Disclosed:
Oct 15, 2020

Realia [realia] <= 1.4.0 (unfixed + closed)

unknown

The Realia plugin for WordPress is vulnerable to Arbitrary Post Deletion in versions up to, and including, 1.4.0. This is due to the 'includes/class-realia-submission.php' file. This makes it possible for unauthenticated attackers to delete any post within the vulnerability's scope.

Affected:
up to 1.4.0
Fix:
No patched version reported
Disclosed:
Oct 15, 2020

Realia [realia] < 1.5 (unfixed + closed)

unknown

Unauthenticated IDOR leading to Arbitrary Post Deletion vulnerability found by Vlad Vector, Erwan LR in WordPress Realia plugin (versions <= 1.4).

Affected:
up to 1.5
Fix:
No patched version reported
Disclosed:
Feb 15, 2020

Realia <= 0.9.1 - Reflected Cross-Site Scripting

medium

The Realia plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 0.9.2 via the 'filter-id' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 0.9.2
Fixed in:
0.9.2
Disclosed:
Mar 6, 2016

Realia [realia] < 0.9.2

unknown

The Realia plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 0.9.2 via the 'filter-id' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 0.9.2
Fixed in:
0.9.2
Disclosed:
Mar 6, 2016

Realia [realia] <= 1.4 (unfixed + closed)

unknown

While investigating an IDOR issue on a premium theme, allowing arbitrary deletion of Ads, submitted by Vlad Vector, the Realia plugin was found to be the root cause. In fact, having this plugin installed (which some themes require) can allow unauthenticated attackers to delete arbitrary posts, by submitting a malici...

Affected:
up to 1.4
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database