Authentication bypass using an alternate path or channel in WP Real Estate Manager plugin for WordPress



Risk High
Patch available NO
Number of vulnerabilities 1
CVE-ID CVE-2025-1515
CWE-ID CWE-288
Exploitation vector Network
Public exploit N/A
Vulnerable software
WP Real Estate Manager
Web applications / Modules and components for CMS

Vendor Chimpstudio

Security Bulletin

This security bulletin contains one high risk vulnerability.

1) Authentication bypass using an alternate path or channel

EUVDB-ID: #VU105445

Risk: High

CVSSv4.0: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2025-1515

CWE-ID: CWE-288 - Authentication Bypass Using an Alternate Path or Channel

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to insufficient identity verification on the LinkedIn login request process. A remote attacker can bypass authentication and log in as any user on the site.

Mitigation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

WP Real Estate Manager: - - 2.8

CPE2.3 External links

https://themeforest.net/item/home-villa-real-estate-wordpress-theme/19446059
https://www.wordfence.com/threat-intel/vulnerabilities/id/84f08111-d116-46f9-9765-28966e338753?source=cve


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###