Executive brief
IMPress for IDX Broker is a WordPress plugin used by real estate professionals to manage property listings and client communications through the IDX Broker platform. An unauthenticated broken authentication vulnerability allows attackers to bypass the login system and gain unauthorized access to user accounts without knowing passwords, potentially exposing client data, property information, and transaction details.
Technical details
The vulnerability is a broken authentication flaw in IMPress for IDX Broker versions 3.3.0 and earlier that allows unauthenticated attackers to bypass the login mechanism and impersonate users. The vulnerability requires network access but no authentication or user interaction. An attacker can exploit this to gain unauthorized access to the plugin's functionality, including client data and property listings. The vulnerability was patched in version 3.3.1; users should immediately update to the patched version.
Affected products
- IMPress IMPress for IDX Broker ≤ 3.3.0
Timeline
- 2026-09-08: disclosed: Vulnerability disclosed by HaiND via Patchstack
- 2026-04-20: reported: Initial report by HaiND
- 2026-09-08: patched: Patched in version 3.3.1