Junglewise Threat Intelligence

CVE-2026-32465: Essential Real Estate PHP Object Injection

CVE-2026-32465 · Severity: high · CVSS 8.8 · Published 2026-08-18

Executive brief

Essential Real Estate is a WordPress plugin that enables real estate property listings and management on WordPress sites. A PHP Object Injection vulnerability in versions up to 5.3.3 allows authenticated customers to execute arbitrary code on the web server, potentially leading to data theft, malware installation, or complete site compromise.

Technical details

The vulnerability is a PHP Object Injection flaw in the Essential Real Estate WordPress plugin versions 5.3.3 and earlier. An authenticated customer-level user can exploit this vulnerability by manipulating serialized data processed by the plugin, triggering unserialization of malicious PHP objects. This allows remote code execution on the server with the privileges of the web application. The attack requires valid customer credentials but does not require administrative access. As of the advisory date, no official patch is available, though Patchstack has released a mitigation rule to block exploitation attempts.

Affected products

  • Essential Real Estate Essential Real Estate <=5.3.3

Timeline

  • 2026-08-18: disclosed
  • 2026-01-19: reported: Initial report by Steven Julian

References