logo

RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites

ID: ca62a2e2-0e8c-5769-8eb0-3971c63ebd53

STIX ID: report--ca62a2e2-0e8c-5769-8eb0-3971c63ebd53

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-04-22

...
...

A critical arbitrary-file-upload vulnerability (CVE-2025-67968) in the RealHomes CRM plugin—bundled with the RealHomes WordPress theme used on over 30,000 sites—allowed any logged-in Subscriber or higher to upload malicious files via a CSV import AJAX handler due to missing permission checks and lack of filetype validation; the issue has been patched in RealHomes CRM 1.0.1 which adds capability checks and filetype validation, and users are advised to update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.