Themes Vulnerabilities

Real Estate 7 < 2.9.5 - Multiple Vulnerabilities

Description

Multiple vulnerabilities was discovered in the 'Real Estate 7 WordPress', tested version — v2.9.4:

- Unauthenticated Reflected XSS
- Authenticated Persistent XSS
- Authenticated Persistent Self-XSS
- IDOR
- Information Exposure

Edit (WPScanTeam):
January 12th - Report Received & Envato Contacted
January 13th - Envato Investigating
January 13th - v2.9.5 released, fixing the issues

Proof of Concept

Affects Themes

Fixed in 2.9.5

References

Miscellaneous

Original Researcher
m0ze
Submitter
m0ze
Submitter twitter
Verified
No

Timeline

Publicly Published
2020-01-14 (about 6 years ago)
Added
2020-01-14 (about 6 years ago)
Last Updated
2021-01-19 (about 5 years ago)

Other