CVE-2024-4274: Essential Real Estate <= 4.4.2 - Insecure Direct Object Reference to Arbitrary Attachment Deletion
The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation on the removepropertyattachmentajax() function in all versions up to, and including, 4.4.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary attachments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/essential-real-estateto a version that resolves this vulnerability.Fixed in 4.4.2 - Compensating control
Restrict WordPress admin/endpoint access so that only users who truly require it (and not subscriber-level accounts) can reach the Essential Real Estate AJAX functionality that calls remove_property_attachment_ajax().
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4274?
CVE-2024-4274 is considered a high severity vulnerability due to the potential unauthorized data loss.
How do I fix CVE-2024-4274?
To fix CVE-2024-4274, update the Essential Real Estate plugin to version 4.4.3 or later.
Who is affected by CVE-2024-4274?
CVE-2024-4274 affects all versions of the Essential Real Estate plugin for WordPress up to and including 4.4.2.
What type of attacks are possible with CVE-2024-4274?
Authenticated attackers, specifically those with subscriber privileges, can exploit CVE-2024-4274 to remove property attachments without proper authorization.
Is there a known exploit for CVE-2024-4274?
As of now, there is no public proof-of-concept exploit reported for CVE-2024-4274, but the vulnerability itself poses significant risks.