Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Essential Real Estate — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Essential Real Estate, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the Essential Real Estate product, categorized under real estate management software with tags related to web application security and data privacy. It collects known security flaws, including cross-site scripting, SQL injection, and improper access control issues affecting this specific vendor’s offerings from 2018 through 2023. By reviewing this data, users can track a vendor's advisories to stay informed about patches, understand a weakness class by seeing how it manifests in similar systems, and look up a product's vulnerability history to assess long-term security posture and remediation trends. This centralized view helps security professionals, auditors, and IT administrators evaluate the risk profile of Essential Real Estate deployments without navigating multiple disparate sources. The content focuses strictly on factual vulnerability data, excluding speculative or unconfirmed reports. All entries are sourced from verified vendor advisories, public CVE databases, and independent security research. This ensures accuracy and reliability for decision-making purposes. Users interested in deeper technical analysis may refer to individual vulnerability details linked within the database. The aggregation covers both critical and low-severity findings, providing a comprehensive overview of the product's security landscape over time. This approach supports proactive security management by highlighting recurring issues and potential attack vectors associated with the Essential Real Estate platform.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-32465 WordPress Essential Real Estate plugin <= 5.3.3 - PHP Object Injection vulnerability CWE-502 8.8 High 2026-08-18
CVE-2025-68071 WordPress Essential Real Estate plugin <= 5.3.2 - Insecure Direct Object References (IDOR) vulnerability CWE-639 6.5 Medium 2025-12-16
CVE-2025-66127 WordPress Essential Real Estate plugin <= 5.3.2 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-12-16
CVE-2025-48126 WordPress Essential Real Estate plugin <= 5.2.9 - Local File Inclusion vulnerability CWE-98 8.1 High 2025-06-09
CVE-2025-30849 WordPress Essential Real Estate plugin <= 5.2.0 - Local File Inclusion Vulnerability CWE-98 8.1 High 2025-04-01
CVE-2025-24698 WordPress Essential Real Estate plugin <= 5.1.8 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2025-01-24
CVE-2024-12329 Essential Real Estate <= 5.1.6 - Missing Authorization to Authenticated (Contributor+) Information Exposure CWE-200 4.3 Medium 2024-12-12
CVE-2024-4273 Essential Real Estate <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2024-06-04
CVE-2024-4274 Essential Real Estate <= 4.4.2 - Insecure Direct Object Reference to Arbitrary Attachment Deletion CWE-639 4.3 Medium 2024-06-04
CVE-2023-6140 Essential Real Estate < 4.4 - Subscriber+ Arbitrary File Upload 8.8AI High AI 2024-01-08
CVE-2023-6141 Essential Real Estate < 4.4.0 - Subscriber+ Stored XSS 5.4AI Medium AI 2024-01-08
CVE-2023-6139 Essential Real Estate < 4.4.0 - Subscriber+ Denial of Service via Arbitrary Option Update 6.5AI Medium AI 2024-01-08
CVE-2023-6827 Essential Real Estate <= 4.3.5 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 7.5 High 2023-12-15
CVE-2022-3933 Essential Real Estate < 3.9.6 - Reflected Cross-Site-Scripting 5.4 - 2022-12-12

All 14 known CVE vulnerabilities affecting Essential Real Estate with full Chinese analysis, references, and POCs where available.