The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8. This is due to insufficient identity verification on the LinkedIn login request process. This makes it possible for unauthenticated attackers to bypass official authentication and log in as any user on the site, including administrators.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 05 Mar 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8. This is due to insufficient identity verification on the LinkedIn login request process. This makes it possible for unauthenticated attackers to bypass official authentication and log in as any user on the site, including administrators. | |
Title | WP Real Estate Manager <= 2.8 - Authentication Bypass via Account Takeover | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-03-05T14:21:10.735Z
Reserved: 2025-02-20T19:58:26.650Z
Link: CVE-2025-1515

Updated: 2025-03-05T14:21:06.245Z

Status : Received
Published: 2025-03-05T10:15:19.850
Modified: 2025-03-05T10:15:19.850
Link: CVE-2025-1515

No data.