Real Estate 7 WordPress Theme Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability allowing arbitrary file uploads has been identified in the Real Estate 7 WordPress theme, in all versions through 3.5.4. The issue arises from inadequate file type validation in the 'template-submit-listing.php' file. This vulnerability enables authenticated attackers with Seller-level access and above to upload arbitrary files to the server, potentially leading to remote code execution if front-end listing submission is enabled.

Impact

Exploitation of this vulnerability could allow for arbitrary file uploads, with the potential for remote code execution if certain conditions are met.

Remediation

Users are advised to update the Real Estate 7 WordPress theme to version 3.5.5 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
7.5
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.