plugin

Realty Workstation Vulnerabilities

6 known security issues reported for the Realty Workstation WordPress plugin. Most recent disclosed Jan 21, 2025.

1 critical 1 high 1 medium

Running Realty Workstation on your site? Check whether your installed version is affected.

Scan your site free

Realty Workstation [realty-workstation] <= 1.0.45 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Realty Workstation Realty Workstation allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Realty Workstation: from n/a through 1.0.45.

Affected:
up to 1.0.45
Fix:
No patched version reported
Disclosed:
Jan 21, 2025

CVE-2025-23477 on NVD →

Realty Workstation <= 1.0.45 - Missing Authorization

medium

The Realty Workstation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.45. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.0.45
Fix:
No patched version reported
Disclosed:
Jan 16, 2025

CVE-2025-23477 on NVD →

Realty Workstation [realty-workstation] <= 1.0.45 (unfixed + closed)

unknown

[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in Realty Workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through 1.0.45.

Affected:
up to 1.0.45
Fix:
No patched version reported
Disclosed:
Oct 28, 2024

CVE-2024-50489 on NVD →

Realty Workstation <= 1.0.45 - Authentication Bypass to Account Takeover

critical

The Realty Workstation plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.45. This is due to the plugin not properly verifying a users identify prior to allowing them to access an account. This makes it possible for unauthenticated attackers to log in as other users, s...

CVSS:
9.8
Affected:
up to 1.0.45
Fix:
No patched version reported
Disclosed:
Oct 25, 2024

CVE-2024-50489 on NVD →

Realty Workstation [realty-workstation] < 1.0.15 (closed)

unknown

[en] The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection

Affected:
up to 1.0.15
Fixed in:
1.0.15
Disclosed:
Jun 6, 2022

CVE-2022-1691 on NVD →

Realty Workstation <= 1.0.9 - Authenticated SQL Injection

high

The Realty Workstation WordPress plugin through 1.0.9 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection

CVSS:
8.8
Affected:
up to 1.0.9
Fixed in:
1.0.10
Disclosed:
May 9, 2022

CVE-2022-1691 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database