Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51526 | The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts. |
Tue, 25 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smartdatasoft
Smartdatasoft essential Wp Real Estate |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:smartdatasoft:essential_wp_real_estate:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Smartdatasoft
Smartdatasoft essential Wp Real Estate |
Fri, 10 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Jan 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts. | |
| Title | Essential WP Real Estate <= 1.1.3 - Missing Authorization to Arbitrary Post/Page Deletion | |
| Weaknesses | CWE-463 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:58:47.869Z
Reserved: 2025-01-09T22:17:39.866Z
Link: CVE-2024-13318
Updated: 2025-01-10T14:50:04.974Z
Status : Analyzed
Published: 2025-01-10T12:15:24.257
Modified: 2025-02-25T16:49:28.007
Link: CVE-2024-13318
No data.
OpenCVE Enrichment
No data.
EUVD