Realty Workstation [realty-workstation] <= 1.0.45 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Realty Workstation Realty Workstation allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Realty Workstation: from n/a through 1.0.45.
- Affected:
- up to 1.0.45
- Fix:
- No patched version reported
- Disclosed:
- Jan 21, 2025
CVE-2025-23477 on NVD →
Realty Workstation <= 1.0.45 - Missing Authorization
medium
The Realty Workstation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.45. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.0.45
- Fix:
- No patched version reported
- Disclosed:
- Jan 16, 2025
CVE-2025-23477 on NVD →
Realty Workstation [realty-workstation] <= 1.0.45 (unfixed + closed)
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in Realty Workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through 1.0.45.
- Affected:
- up to 1.0.45
- Fix:
- No patched version reported
- Disclosed:
- Oct 28, 2024
CVE-2024-50489 on NVD →
Realty Workstation <= 1.0.45 - Authentication Bypass to Account Takeover
critical
The Realty Workstation plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.45. This is due to the plugin not properly verifying a users identify prior to allowing them to access an account. This makes it possible for unauthenticated attackers to log in as other users, s...
- CVSS:
- 9.8
- Affected:
- up to 1.0.45
- Fix:
- No patched version reported
- Disclosed:
- Oct 25, 2024
CVE-2024-50489 on NVD →
Realty Workstation [realty-workstation] < 1.0.15 (closed)
unknown
[en] The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection
- Affected:
- up to 1.0.15
- Fixed in:
- 1.0.15
- Disclosed:
- Jun 6, 2022
CVE-2022-1691 on NVD →
Realty Workstation <= 1.0.9 - Authenticated SQL Injection
high
The Realty Workstation WordPress plugin through 1.0.9 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection
- CVSS:
- 8.8
- Affected:
- up to 1.0.9
- Fixed in:
- 1.0.10
- Disclosed:
- May 9, 2022
CVE-2022-1691 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database