RateMyAgent Official
RateMyAgent Official has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for RateMyAgent Official has a vendor fix available, so running the current release closes it.
All of these findings were reported by Dhabaleshwar Das. RateMyAgent Official is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-0801RateMyAgent Official <= 1.4.0 - Cross-Site Request Forgery to API Key Update
Read the full analysisVulnerability Records

RateMyAgent Official
Author
ratemyagent
RateMyAgent Official Plugin allows you to display your 4 & 5-star reviews on your website as well as your property listing and sale data. Current Features: * Multiple review layouts to choose from * Listing carousel * Sold Property carousel * Theme colour customization * Step by step wizard to set up Using shortcodes Under the hood, the blocks are just a wrapper on short codes which allows people who use other page builders ( elementor, Beaver Builder, etc) and template developers to add them too. Review Carousel [rma-review-carousel template_type="full" is_leasing="true" profile_type="agency" profile_code="aaXXXX" ] [/rma-review-carousel] Options: is_leasing: true false (default) profile_type: agent (default) agency mortgage-broker profile_code: the profile code of the agent/agency template_type : full (default) no-property review-only full-review heading: string (optional) (note: you can use {reviewCount} in the heading to print the profile’s total review count. like “350 Happy customers”) Listing Carousel [rma-listings-carousel profile_code="aaXXXX" profile_type="agent" template_type="full" listing_status="both" ][/rma-listings-carousel] profile_type: agent (default) agency profile_code: the profile code of the agent/agency template_type: full (default) listing_status: both (default) – Shows both active and sold listings active – Shows only active listings sold – Shows only sold listings Note: If you are using the default value for any option, you do not need to supply it
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C