CVE-2025-39459
Real Estate 7 WordPress
Minimum safe version
3.5.5
Update to 3.5.5 or later to address 30 fixable vulnerabilities
WP Pro Real Estate 7 <= 3.5.4 - Authenticated (Custom) Arbitrary File Upload
CVE-2024-13421
Real Estate 7 < 3.3.5 - Reflected XSS
Real Estate 7 < 3.0.5 - Unauthenticated Reflected XSS
Real Estate 7 < 3.0.4 - Unauthenticated Reflected XSS
Real Estate 7 < 2.9.5 - Multiple Vulnerabilities
Real Estate 7 < 2.9.1 - Stored XSS & IDOR
Real Estate 7 < 3.3.5 - Multiple CSRF
WordPress Real Estate 7 Theme <= 3.3.4 is vulnerable to Broken Access Control
Real Estate 7 Theme <= 3.3.4 - Unauthenticated Arbitrary Email Sending
WordPress Real Estate 7 Theme <= 3.3.4 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress Real Estate 7 Theme <= 3.3.4 is vulnerable to Cross Site Scripting (XSS)
Real Estate 7 <= 3.3.4 - Cross-Site Request Forgery
Real Estate 7 <= 3.3.4 - Reflected Cross-Site Scripting via ct_additional_features
CVE-2022-47146
Real Estate 7 WordPress Theme < 2.9.1 - Stored Cross-Site Scripting
Real Estate 7 WordPress < 2.9.5 - Multiple Vulnerabilities
Real Estate 7 <= 3.0.3 - Reflected Cross-Site Scripting
Real Estate 7 WordPress < 3.0.6 - Reflected Cross-Site Scripting
WordPress Real Estate 7 theme 2.5.6 - Authenticated Arbitrary File Upload vulnerability
WordPress Real Estate 7 premium theme <= 2.9.4 - Information Disclosure vulnerability
WordPress Real Estate 7 premium theme <= 2.9.4 - Insecure Direct Object References (IDOR) vulnerability
WordPress Real Estate 7 premium theme <= 2.9.4 - Persistent Self Cross-Site Scripting (XSS) vulnerability
WordPress Real Estate 7 premium theme <= 2.9.4 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
WordPress Real Estate 7 premium theme <= 2.9.4 - Unauthenticated Cross-Site Scripting (XSS) vulnerability
WordPress Real Estate 7 premium theme <= 3.0.3 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Real Estate 7 premium theme <= 3.0.4 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Real Estate 7 premium theme <= 3.1.0 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2021-24387