The RealHome theme and the Easy Real Estate plugins for WordPress are vulnerable to two critical severity flaws that allow unauthenticated users to gain administrative privileges. Although the two flaws were discovered in September 2024 by Patchstack, and multiple attempts were made to contact the vendor (InspiryThemes), the researchers say they have not received a response. Also, Patchstack says the vendor released three versions since September, but no security fixes to address the critical issues were introduced. Hence, the issues remain unfixed and exploitable. The RealHome theme and Easy Real Estate are among the most popular themes and plugins designed for use in real estate websites. According to Envanto Market data, the RealHome theme is used in 32,600 websites. The first flaw, which impacts RealHome theme, is an unauthenticated privilege escalation problem tracked as CVE-2024-32444 (CVSS score: 9.8). The theme allows users to register new accounts via the inspiry_ajax_register function, however, it does not properly check authorization or implement a nonce validation. If registration is enabled on the website, attackers can arbitrarily specify their role as "Administrator" in a specially crafted HTTP request to the registration function, essentially bypassing security checks. Once registered as an administrator, the attacker can subsequently gain full control of the WordPress site, including performing content manipulation, planting scripts, and accessing user or ot...
Critical zero-days impact premium WordPress real estate plugins
BleepingComputer
·Bill Toulas
·Published Jan 22, 2025
·Updated
Affected Software
4 affected components
InspiryThemes RealHome
InspiryThemes Easy Real Estate
InspiryThemes RealHome
InspiryThemes Easy Real Estate
Frequently Asked Questions
1
What are the critical vulnerabilities mentioned in the article?
The vulnerabilities allow unauthenticated users to gain administrative privileges on the affected WordPress plugins.
2
Which WordPress plugins are affected by these vulnerabilities?
The affected plugins are the RealHome theme and the Easy Real Estate plugins by InspiryThemes.
3
When were these critical vulnerabilities discovered?
The vulnerabilities were discovered in September 2023.
4
What is the severity level of the flaws found in the plugins?
The flaws are considered to have critical severity.
5
Who is the vendor of the affected products mentioned in the article?
The vendor of the affected products is InspiryThemes.