theme

Real Spaces Vulnerabilities

4 known security issues reported for the Real Spaces WordPress theme. Most recent disclosed Aug 18, 2025.

1 critical 1 high

Running Real Spaces on your site? Check whether your installed version is affected.

Scan your site free

Real Spaces - WordPress Properties Directory Theme <= 3.6 - Unauthenticated Privilege Escalation to Administrator via 'imic_agent_register'

critical

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to arbitr...

CVSS:
9.8
Affected:
up to 3.6
Fixed in:
3.6.1
Disclosed:
Aug 18, 2025

CVE-2025-6758 on NVD →

Real Spaces - WordPress Properties Directory Theme <= 3.5 - Authenticated (Subscriber+) Privilege Escalation to Administrator via 'change_role_member'

high

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, and including, 3.5. This is due to a lack of restriction in the profile update role. This makes it possible for unauthenticated attackers to arbi...

CVSS:
8.8
Affected:
up to 3.5
Fixed in:
3.6
Disclosed:
Aug 18, 2025

CVE-2025-8218 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database