RH - Real Estate WordPress Theme <= 4.4.0 - Authenticated (Subscriber+) Privilege Escalation

2025-06-09 14:53
Thái An

Strategic Overview

Status
Patched in 4.4.1
Affected Version<= 4.4.0
CVSS8.8High
CVECVE-2025-4601
View all RH - Real Estate WordPress Theme vulnerabilities

Vulnerability Overview

The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to the theme not properly restricting user roles that can be updated as part of the inspiry_update_profile() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to set their role to that of an administrator. The vulnerability was partially patched in version 4.4.0, and fully patched in version 4.4.1. CVE-2025-49867 is likely a duplicate of this.

Technical Analysis

REMEDIATION: Update to version 4.4.1, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C