Junglewise Threat Intelligence

CVE-2026-57641: Contempoinc Real Estate 7 CSRF in WordPress theme

CVE-2026-57641 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Technologies: Contempoinc Real Estate 7.

Executive brief

Real Estate 7 is a popular WordPress theme used for building property listing and real estate websites. A security flaw in versions 3.5.9 and earlier could allow an attacker to trick an administrator into performing unintended actions on the site, such as changing settings or deleting content, by getting them to click a malicious link. This could lead to unauthorized changes to the website's configuration or a disruption of service.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Real Estate 7 theme for WordPress (versions up to and including 3.5.9). The issue stems from a lack of proper nonce validation on sensitive administrative functions. An unauthenticated attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it via social engineering (e.g., a phishing link). Successful exploitation allows the attacker to perform unauthorized actions with the privileges of the victim user. The vulnerability is addressed in version 3.6.0.

Affected products

  • Contempoinc Real Estate 7 <= 3.5.9

Timeline

  • 2026-04-30: disclosed: Reported by João Pedro S Alcântara (Kinorth)
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Version 3.6.0 released to address the issue

References