HomeSweet - Real Estate WordPress Theme <= 1.4 - Insecure Direct Object Reference
mediumThe HomeSweet - Real Estate WordPress Theme is vulnerable to Insecure Direct Object Reference via 'property_id=2769&remove_property_form=' in versions up to, and including, 1.4. This makes it possible for authenticated attackers to delete arbitrary ads within the vulnerable service.
- CVSS:
- 5.4
- Affected:
- up to 1.4
- Fix:
- No patched version reported
- Disclosed:
- Jun 17, 2020