Executive brief
The Real Estate 7 theme for WordPress, which is used to build property listing and real estate websites, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability to interact directly with the website's database. This could lead to the theft of sensitive customer information, unauthorized access to site data, or disruption of business operations.
Technical details
A SQL injection vulnerability exists in the Real Estate 7 WordPress theme (versions <= 3.5.9) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to unauthenticated remote attackers via the network without any user interaction. Successful exploitation allows an attacker to bypass authentication, extract sensitive data from the database, or potentially modify database records. The vulnerability has been addressed in version 3.6.0.
Affected products
- contempoinc Real Estate 7 <= 3.5.9
Timeline
- 2026-04-30: other: Reported by João Pedro S Alcântara (Kinorth)
- 2026-06-17: advisory: Patchstack advisory published
- 2026-06-26: disclosed: CVE published to NVD