PT-2026-72879 · WordPress · Real Estate Manager Pro
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Real Estate Manager Pro versions prior to 12.8.7
Description
Improper capability handling in the
allow attachment actions() function allows authenticated attackers with Subscriber-level access or higher to escalate their privileges to Administrator. The issue occurs when the function treats a target user ID as a media attachment ID during capability checks, enabling the modification of an administrator account if the targeted user ID matches the ID of an existing media attachment.Recommendations
Update Real Estate Manager Pro to a version newer than 12.8.6.
As a temporary mitigation, restrict access to user management functions for accounts with Subscriber-level privileges.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Real Estate Manager Pro