Resido - Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side Request Forgery and API Key Settings Update

2025-03-13 00:00
Lucio Sá

Strategic Overview

Status
Patched in 3.6.1
Affected Version<= 3.6
CVSS5.3Medium
CVECVE-2025-1285
View all Resido - Real Estate WordPress Theme vulnerabilities

Vulnerability Overview

The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api_key and save_api_key AJAX actions in all versions up to, and including, 3.6. This makes it possible for unauthenticated attackers to issue requests to internal services and update API key details.

Technical Analysis

REMEDIATION: Update to version 3.6.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C