theme

Realestate 7 Vulnerabilities

45 known security issues reported for the Realestate 7 WordPress theme. Most recent disclosed Jun 29, 2026.

2 critical 4 high 9 medium

Running Realestate 7 on your site? Check whether your installed version is affected.

Scan your site free

Real Estate 7 WordPress <= 3.5.9 - Unauthenticated Stored Cross-Site Scripting

high

The Real Estate 7 WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
7.2
Affected:
up to 3.5.9
Fixed in:
3.6.0
Disclosed:
Jun 29, 2026

CVE-2026-57343 on NVD →

Real Estate 7 WordPress <= 3.5.9 - Cross-Site Request Forgery

medium

The Real Estate 7 WordPress theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted the...

CVSS:
4.3
Affected:
up to 3.5.9
Fixed in:
3.6.0
Disclosed:
Jun 26, 2026

CVE-2026-57641 on NVD →

Real Estate 7 WordPress <= 3.5.9 - Unauthenticated SQL Injection

high

The Real Estate 7 WordPress theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...

CVSS:
7.5
Affected:
up to 3.5.9
Fixed in:
3.6.0
Disclosed:
Jun 17, 2026

CVE-2026-54827 on NVD →

Real Estate 7 WordPress [realestate-7] < 3.5.3

unknown

[en] Incorrect Privilege Assignment vulnerability in Contempo Themes Real Estate 7 allows Privilege Escalation.This issue affects Real Estate 7: from n/a through 3.5.2.

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
May 19, 2025

CVE-2025-39459 on NVD →

Real Estate 7 <= 3.5.2 - Unauthenticated Privilege Escalation

critical

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

CVSS:
9.8
Affected:
up to 3.5.2
Fixed in:
3.5.3
Disclosed:
Apr 17, 2025

CVE-2025-39459 on NVD →

WP Pro Real Estate 7 <= 3.5.4 - Authenticated (Custom) Arbitrary File Upload

high

The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with Seller-level access and above, to upload arbitrary...

CVSS:
8.8
Affected:
up to 3.5.4
Fixed in:
3.5.5
Disclosed:
Mar 31, 2025

CVE-2025-2891 on NVD →

Real Estate 7 WordPress [realestate-7] < 3.5.2

unknown

[en] The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administ...

Affected:
up to 3.5.2
Fixed in:
3.5.2
Disclosed:
Feb 12, 2025

CVE-2024-13421 on NVD →

Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administrator

critical

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrativ...

CVSS:
9.8
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Feb 11, 2025

CVE-2024-13421 on NVD →

Real Estate 7 WordPress [realestate-7] < 3.3.5

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions.

Affected:
up to 3.3.5
Fixed in:
3.3.5
Disclosed:
Mar 27, 2023

CVE-2022-47146 on NVD →

Real Estate 7 WordPress [realestate-7] < 3.3.5

unknown

Update the WordPress Real Estate 7 theme to the latest available version (at least 3.3.5). FearZzZz discovered and reported this Broken Access Control vulnerability in WordPress Real Estate 7 Theme. This vulnerability has been fixed in version 3.3.5.

Affected:
up to 3.3.5
Fixed in:
3.3.5
Disclosed:
Mar 13, 2023

Real Estate 7 Theme <= 3.3.4 - Unauthenticated Arbitrary Email Sending

medium

The Real Estate 7 Theme for WordPress suffers from an Open Mailer vulnerability in versions up to, and including, 3.3.4. This is due to a lack of authorization in the /includes/ajax-submit-favorites.php and /includes/ajax-submit-listings.php files which are reachable via AJAX call but also directly via POST. This makes...

CVSS:
5.8
Affected:
up to 3.3.4
Fixed in:
3.3.5
Disclosed:
Mar 9, 2023

Real Estate 7 WordPress [realestate-7] < 3.3.5

unknown

The Real Estate 7 Theme for WordPress suffers from an Open Mailer vulnerability in versions up to, and including, 3.3.4. This is due to a lack of authorization in the /includes/ajax-submit-favorites.php and /includes/ajax-submit-listings.php files which are reachable via AJAX call but also directly via POST. This makes...

Affected:
up to 3.3.5
Fixed in:
3.3.5
Disclosed:
Mar 9, 2023

Real Estate 7 WordPress [realestate-7] < 3.3.5

unknown

Update the WordPress Real Estate 7 theme to the latest available version (at least 3.3.5). FearZzZz discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Real Estate 7 Theme. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their c...

Affected:
up to 3.3.5
Fixed in:
3.3.5
Disclosed:
Mar 2, 2023

Real Estate 7 WordPress [realestate-7] < 3.3.5

unknown

Update the WordPress Real Estate 7 theme to the latest available version (at least 3.3.5). FearZzZz discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Real Estate 7 Theme. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML pa...

Affected:
up to 3.3.5
Fixed in:
3.3.5
Disclosed:
Mar 2, 2023

Real Estate 7 <= 3.3.4 - Cross-Site Request Forgery

medium

The Real Estate 7 theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.4. This is due to missing or incorrect nonce validation on several of its AJAX actions. This makes it possible for unauthenticated attackers to invoke those functions via a forged request granted they...

CVSS:
5.4
Affected:
up to 3.3.4
Fixed in:
3.3.5
Disclosed:
Mar 1, 2023

Real Estate 7 WordPress [realestate-7] < 3.3.5

unknown

The Real Estate 7 theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.4. This is due to missing or incorrect nonce validation on several of its AJAX actions. This makes it possible for unauthenticated attackers to invoke those functions via a forged request granted they...

Affected:
up to 3.3.5
Fixed in:
3.3.5
Disclosed:
Mar 1, 2023

Real Estate 7 <= 3.3.4 - Reflected Cross-Site Scripting via ct_additional_features

medium

The Real Estate 7 Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ct_additional_features’ parameter in versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
6.1
Affected:
up to 3.3.4
Fixed in:
3.3.5
Disclosed:
Feb 28, 2023

Real Estate 7 WordPress [realestate-7] < 3.3.5

unknown

The Real Estate 7 Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ct_additional_features’ parameter in versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

Affected:
up to 3.3.5
Fixed in:
3.3.5
Disclosed:
Feb 28, 2023

Real Estate 7 Theme <= 3.3.1 - Stored Cross-Site Scripting

high

The Real Estate 7 Theme for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...

CVSS:
7.2
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Feb 20, 2023

CVE-2022-47146 on NVD →

Real Estate 7 WordPress [realestate-7] < 3.1.1

unknown

[en] The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Jul 6, 2021

CVE-2021-24387 on NVD →

WP Pro Real Estate 7 < 3.1.1 - Reflected Cross-Site Scripting

medium

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context.

CVSS:
6.1
Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Jun 10, 2021

CVE-2021-24387 on NVD →

Real Estate 7 WordPress [realestate-7] < 3.1.1

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress Real Estate 7 premium theme (versions <= 3.1.0). Vulnerable parameter: "&ct_community=".

Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Jun 3, 2021

Real Estate 7 WordPress [realestate-7] < 3.0.5

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by Ex.Mi in WordPress Real Estate 7 premium theme (versions <= 3.0.4).

Affected:
up to 3.0.5
Fixed in:
3.0.5
Disclosed:
Oct 7, 2020

Real Estate 7 WordPress < 3.0.6 - Reflected Cross-Site Scripting

medium

The Real Estate 7 Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters (ct_sqft_from, ct_sqft_to, ct_lotsize_from, ct_lotsize_to, & ct_mls) in versions before 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...

CVSS:
6.1
Affected:
up to 3.0.5
Fixed in:
3.0.6
Disclosed:
Aug 29, 2020

Real Estate 7 WordPress [realestate-7] < 3.0.6

unknown

The Real Estate 7 Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters (ct_sqft_from, ct_sqft_to, ct_lotsize_from, ct_lotsize_to, & ct_mls) in versions before 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...

Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Aug 29, 2020

Real Estate 7 <= 3.0.3 - Reflected Cross-Site Scripting

medium

The Real Estate 7 theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ct_keyword’ parameter in versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 3.0.3
Fixed in:
3.0.4
Disclosed:
Jul 23, 2020

Real Estate 7 WordPress [realestate-7] < 3.0.4

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Real Estate 7 premium theme (versions <= 3.0.3).

Affected:
up to 3.0.4
Fixed in:
3.0.4
Disclosed:
Jul 23, 2020

Real Estate 7 WordPress [realestate-7] < 3.0.4

unknown

The Real Estate 7 theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ct_keyword’ parameter in versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

Affected:
up to 3.0.4
Fixed in:
3.0.4
Disclosed:
Jul 23, 2020

Real Estate 7 WordPress < 2.9.5 - Multiple Vulnerabilities

medium

The Real Estate 7 WordPress theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Scripting, Insecure Direct Object Reference, and Sensitive Information Exposure in versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping, along with exposure of email addresses...

CVSS:
6.4
Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jan 14, 2020

Real Estate 7 WordPress [realestate-7] < 2.9.5

unknown

Unauthenticated Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Real Estate 7 premium theme (versions <= 2.9.4).

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jan 14, 2020

Real Estate 7 WordPress [realestate-7] < 2.9.5

unknown

The Real Estate 7 WordPress theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Scripting, Insecure Direct Object Reference, and Sensitive Information Exposure in versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping, along with exposure of email addresses...

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jan 14, 2020

Real Estate 7 WordPress [realestate-7] < 2.9.5

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Real Estate 7 premium theme (versions <= 2.9.4).

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jan 14, 2020

Real Estate 7 WordPress [realestate-7] < 2.9.5

unknown

Sensitive Information Disclosure vulnerability discovered by m0ze in WordPress Real Estate 7 premium theme (versions <= 2.9.4).

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jan 14, 2020

Real Estate 7 WordPress [realestate-7] < 2.9.5

unknown

Persistent Self Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Real Estate 7 premium theme (versions <= 2.9.4).

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jan 14, 2020

Real Estate 7 WordPress [realestate-7] < 2.9.5

unknown

Insecure Direct Object References (IDOR) vulnerability discovered by m0ze in WordPress Real Estate 7 premium theme (versions <= 2.9.4).

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jan 14, 2020

Real Estate 7 WordPress Theme < 2.9.1 - Stored Cross-Site Scripting

medium

The Real Estate 7 WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the template-edit-listing.php and template-submit-listing.php php files in versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 2.9.1
Fixed in:
2.9.1
Disclosed:
Jul 20, 2019

Real Estate 7 WordPress [realestate-7] < 2.9.1

unknown

The Real Estate 7 WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the template-edit-listing.php and template-submit-listing.php php files in versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

Affected:
up to 2.9.1
Fixed in:
2.9.1
Disclosed:
Jul 20, 2019

Real Estate 7 WordPress [realestate-7] < 2.5.9

unknown

The Authenticated Arbitrary File Upload vulnerability found by WPHutte in WordPress Real Estate 7 theme version 2.5.6 Update WordPress Real Estate 7 theme to the latest available version (at least version 2.5.9)

Affected:
up to 2.5.9
Fixed in:
2.5.9
Disclosed:
Apr 15, 2017

Real Estate 7 WordPress [realestate-7] < 3.0.5

unknown

An Unauthenticated Reflected XSS vulnerability was discovered in the Real Estate 7 theme v3.0.4 for WordPress. Vulnerable parameters: ct_sqft_from, ct_sqft_to, ct_lotsize_from, ct_lotsize_to, ct_mls. Edit (WPScanTeam): The issue has been hot-fixed in 3.0.4. So the fixed in has been set to 3.0.5 (the next version...

Affected:
up to 3.0.5
Fixed in:
3.0.5

Real Estate 7 WordPress [realestate-7] < 3.3.5

unknown

The theme does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 3.3.5
Fixed in:
3.3.5

Real Estate 7 WordPress [realestate-7] < 3.0.4

unknown

An Unauthenticated Reflected XSS vulnerability was discovered in the Real Estate 7 theme v3.0.2 and v3.0.3 for WordPress.

Affected:
up to 3.0.4
Fixed in:
3.0.4

Real Estate 7 WordPress [realestate-7] < 2.9.5

unknown

Multiple vulnerabilities was discovered in the &#039;Real Estate 7 WordPress&#039;, tested version &mdash; v2.9.4: - Unauthenticated Reflected XSS - Authenticated Persistent XSS - Authenticated Persistent Self-XSS - IDOR - Information Exposure Edit (WPScanTeam): January 12th - Report Received &amp; Envato...

Affected:
up to 2.9.5
Fixed in:
2.9.5

Real Estate 7 WordPress [realestate-7] < 2.9.1

unknown

The &#039;Real Estate 7&#039; premium WordPress theme is vulnerable to persistent XSS injection that allows an attacker to inject JavaScript or HTML code into the website front-end. There is also an Insecure Direct Object Reference issue, allowing unauthorized users to edit listings they should not have access to. D...

Affected:
up to 2.9.1
Fixed in:
2.9.1

Real Estate 7 WordPress [realestate-7] < 3.3.5

unknown

The theme does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, for example create/delete arbitrary lead alerts, manipulate properties (add/remove from favourite) etc

Affected:
up to 3.3.5
Fixed in:
3.3.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database