Critical zero-days impact premium WordPress real estate plugins
ID: 391c6261-e0ec-5588-8fab-64d4c157c2a8
STIX ID: report--391c6261-e0ec-5588-8fab-64d4c157c2a8
Feed Name: Bleeping Computer
Two critical unauthenticated privilege-escalation vulnerabilities were disclosed in the RealHome WordPress theme and the Easy Real Estate plugin (CVE-2024-32444 and CVE-2024-32555, both CVSS 9.8). The first allows attackers to register as an Administrator via a flawed registration endpoint; the second permits social-login bypass by logging in with a target admin's email without verification. The vendor has not released fixes despite being contacted, leaving thousands of sites at high risk; site owners are advised to disable the affected add-ons and restrict registrations until patches are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
