Cross Site Request Forgery Vulnerability in Real Estate 7 by WordPress
CVE-2026-57641

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 June 2026

What is CVE-2026-57641?

An unauthenticated Cross Site Request Forgery (CSRF) vulnerability exists in the Real Estate 7 theme for WordPress, specifically in versions up to 3.5.9. This flaw allows attackers to exploit user sessions by forcing an authenticated user to execute unwanted actions on behalf of the attacker, compromising the integrity and security of the website.

Affected Version(s)

Real Estate 7 <= 3.5.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.