Privilege Escalation Vulnerability in Real Spaces WordPress Theme
CVE-2025-8218

8.8HIGH

What is CVE-2025-8218?

The Real Spaces - WordPress Properties Directory Theme contains a vulnerability that allows unauthenticated users to exploit the 'change_role_member' parameter. This flaw permits attackers to elevate their user role without proper restrictions during profile updates. As a result, they could gain unauthorized administrative access, compromising the integrity and security of the website. All versions up to and including 3.5 are affected, making it crucial for users to update and secure their installations to prevent exploitation.

Affected Version(s)

Real Spaces - WordPress Properties Directory Theme * <= 3.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alyudin Nafiie
.
CVE-2025-8218 : Privilege Escalation Vulnerability in Real Spaces WordPress Theme