logo

Critical zero-days impact premium WordPress real estate plugins

ID: 391c6261-e0ec-5588-8fab-64d4c157c2a8

STIX ID: report--391c6261-e0ec-5588-8fab-64d4c157c2a8

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-01-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Two critical unauthenticated privilege-escalation vulnerabilities were disclosed in the RealHome WordPress theme and the Easy Real Estate plugin (CVE-2024-32444 and CVE-2024-32555, both CVSS 9.8). The first allows attackers to register as an Administrator via a flawed registration endpoint; the second permits social-login bypass by logging in with a target admin's email without verification. The vendor has not released fixes despite being contacted, leaving thousands of sites at high risk; site owners are advised to disable the affected add-ons and restrict registrations until patches are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.