CVE-2023-4239

The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webcodingplace:real_estate_manager:*:*:*:*:*:wordpress:*:*

History

08 Apr 2026, 19:18

Type Values Removed Values Added
Summary (en) The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7.1 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update. (en) The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.
CWE CWE-269

21 Nov 2024, 08:34

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/6.7.1/classes/shortcodes.class.php#L1439 - Exploit () https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/6.7.1/classes/shortcodes.class.php#L1439 - Exploit
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/d83d1fd0-6e21-406e-a7c0-89d26eabbb32?source=cve - Third Party Advisory () https://www.wordfence.com/threat-intel/vulnerabilities/id/d83d1fd0-6e21-406e-a7c0-89d26eabbb32?source=cve - Third Party Advisory
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 8.8

07 Nov 2023, 04:22

Type Values Removed Values Added
CWE CWE-269

15 Aug 2023, 17:00

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:webcodingplace:real_estate_manager:*:*:*:*:*:wordpress:*:*
First Time Webcodingplace
Webcodingplace real Estate Manager
References (MISC) https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/6.7.1/classes/shortcodes.class.php#L1439 - (MISC) https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/6.7.1/classes/shortcodes.class.php#L1439 - Exploit
References (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/d83d1fd0-6e21-406e-a7c0-89d26eabbb32?source=cve - (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/d83d1fd0-6e21-406e-a7c0-89d26eabbb32?source=cve - Third Party Advisory

09 Aug 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-09 03:15

Updated : 2026-04-08 19:18


NVD link : CVE-2023-4239

Mitre link : CVE-2023-4239

CVE.ORG link : CVE-2023-4239


JSON object : View

Products Affected

webcodingplace

  • real_estate_manager
CWE
CWE-269

Improper Privilege Management