Resido - Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side Request Forgery and API Key Settings Update
2025-03-13 00:00
Lucio SáStrategic Overview
StatusPatched in 3.6.1
Affected ThemeResido - Real Estate WordPress Theme
Affected Version
<= 3.6CVSS5.3Medium
CVE
CVE-2025-1285Vulnerability Overview
The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api_key and save_api_key AJAX actions in all versions up to, and including, 3.6. This makes it possible for unauthenticated attackers to issue requests to internal services and update API key details.
Technical Analysis
REMEDIATION: Update to version 3.6.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C