Privilege Escalation in Realty Portal β Agent Plugin for WordPress
CVE-2025-6190
8.8HIGH
What is CVE-2025-6190?
The Realty Portal β Agent plugin for WordPress has a vulnerability that enables privilege escalation due to inadequate authorization checks in the rp_user_profile() AJAX handler, impacting versions 0.1.0 through 0.3.9. This flaw allows authenticated attackers with Subscriber-level access and higher to manipulate client-supplied meta key-value pairs, directly interfacing with the update_user_meta() function without proper safeguards. As a result, attackers can overwrite the wp_capabilities meta value, potentially granting themselves administrator privileges. This could lead to severe security risks, compromising the integrity and stability of the WordPress environment.
Affected Version(s)
Realty Portal β Agent * <= 0.3.9