theme

Reality Vulnerabilities

11 known security issues reported for the Reality WordPress theme. Most recent disclosed Jul 29, 2020.

3 medium

Running Reality on your site? Check whether your installed version is affected.

Scan your site free

Reality [reality] < 2.5.6

unknown

Multiple Reflected Cross-Site Scripting (XSS) vulnerabilities found by Vlad Vector in WordPress Reality premium theme (versions <= 2.5.5).

Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Jul 29, 2020

Reality | Estate Multipurpose WordPress Theme <= 2.5.5 - Reflected Cross-Site Scripting

medium

The Reality theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on the 'keyword' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...

CVSS:
6.1
Affected:
up to 2.5.5
Fixed in:
2.5.6
Disclosed:
Jun 20, 2020

Reality | Estate Multipurpose WordPress Theme <= 2.5.3 - Reflected Cross-Site Scripting

medium

The Reality | Estate Multipurpose WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'label' & 'tab' parameters in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...

CVSS:
6.1
Affected:
up to 2.5.3
Fixed in:
2.5.6
Disclosed:
Jun 20, 2020

Reality [reality] < 2.5.6

unknown

The Reality theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on the 'keyword' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...

Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Jun 20, 2020

Reality [reality] < 2.5.6

unknown

The Reality | Estate Multipurpose WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'label' & 'tab' parameters in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...

Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Jun 20, 2020

Reality [reality] < 2.5.2

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by m0ze in WordPress Reality premium theme (versions <= 2.5.1).

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Feb 7, 2020

Reality <= 2.3.0 - Stored Cross-Site Scripting

medium

The Reality theme for WordPress is vulnerable to Stored Cross-Site Scripting via the property and user pages in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute w...

CVSS:
6.4
Affected:
up to 2.3.0
Fixed in:
2.4.0
Disclosed:
Sep 8, 2019

Reality [reality] < 2.4.0

unknown

The Reality theme for WordPress is vulnerable to Stored Cross-Site Scripting via the property and user pages in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute w...

Affected:
up to 2.4.0
Fixed in:
2.4.0
Disclosed:
Sep 8, 2019

Reality [reality] < 2.4.0

unknown

----[]- Persistent XSS on any property page: -[]---- Vulnerable input fields: 1 - Description &amp; Price -&gt; &#039;PRICE POSTFIX TEXT&#039; and &#039;SECOND PRICE POSTFIX TEXT&#039;; 2 - Additional Information -&gt; &#039;TITLE&#039; and &#039;VALUE&#039;; 3 - Location &amp; Map -&gt; &#039;ADDRESS *&#039;. P...

Affected:
up to 2.4.0
Fixed in:
2.4.0

Reality [reality] < 2.5.3

unknown

Reflected XSS was discovered in the &laquo;Reality | Estate Multipurpose WordPress Theme&raquo;, tested version &mdash; v2.5.1 Edit (WPScanTeam): January 16th, 2020 - Report Received &amp; Envato Contacted January 17th, 2020 - Envato Investigating February 6th, 2020 - Envato Contacted Again for Updates February...

Affected:
up to 2.5.3
Fixed in:
2.5.3

Reality [reality] < 2.5.6

unknown

An Unauthenticated &amp; Authenticated Reflected XSS vulnerabilities was discovered in the Reality theme through 2.5.3 and 2.5.5 for WordPress.

Affected:
up to 2.5.6
Fixed in:
2.5.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database