Cross Site Request Forgery Vulnerability in Real Estate 7 by WordPress
CVE-2026-57641
6.5MEDIUM
What is CVE-2026-57641?
An unauthenticated Cross Site Request Forgery (CSRF) vulnerability exists in the Real Estate 7 theme for WordPress, specifically in versions up to 3.5.9. This flaw allows attackers to exploit user sessions by forcing an authenticated user to execute unwanted actions on behalf of the attacker, compromising the integrity and security of the website.
Affected Version(s)
Real Estate 7 <= 3.5.9
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program