Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50776 | The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several pages/post types in all versions up to, and including, 5.1.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to access invoices and transaction logs |
Thu, 05 Jun 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
G5plus
G5plus essential Real Estate |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:g5plus:essential_real_estate:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
G5plus
G5plus essential Real Estate |
Thu, 12 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Dec 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several pages/post types in all versions up to, and including, 5.1.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to access invoices and transaction logs | |
| Title | Essential Real Estate <= 5.1.6 - Missing Authorization to Authenticated (Contributor+) Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:34:22.508Z
Reserved: 2024-12-06T21:32:09.785Z
Link: CVE-2024-12329
Updated: 2024-12-12T14:46:12.088Z
Status : Analyzed
Published: 2024-12-12T07:15:10.607
Modified: 2025-06-05T16:05:14.507
Link: CVE-2024-12329
No data.
OpenCVE Enrichment
No data.
EUVD