CVE-2023-4239
Real Estate Manager <= 7.2 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7.1 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.
El plugin Real Estate Manager para WordPress es vulnerable a la escalada de privilegios en versiones hasta, e incluyendo, la 6.7.1 debido a una restricción insuficiente en la función "rem_save_profile_front". Esto hace posible que atacantes autenticados, con permisos mínimos como un suscriptor, modifiquen su rol de usuario suministrando el parámetro "wp_capabilities" durante una actualización de perfil.
The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-08-08 CVE Reserved
- 2023-08-08 CVE Published
- 2025-02-05 CVE Updated
- 2025-02-05 First Exploit
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.wordfence.com/threat-intel/vulnerabilities/id/d83d1fd0-6e21-406e-a7c0-89d26eabbb32?source=cve | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/6.7.1/classes/shortcodes.class.php#L1439 | 2025-02-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Webcodingplace Search vendor "Webcodingplace" | Real Estate Manager Search vendor "Webcodingplace" for product "Real Estate Manager" | <= 6.7.1 Search vendor "Webcodingplace" for product "Real Estate Manager" and version " <= 6.7.1" | wordpress |
Affected
|