← WordPress Vulnerabilities
WordPress security by component

Contempo Real Estate Core

Contempo Real Estate Core is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Apr 01, 2025; the highest CVE/CNA score is 6.4.

Plugin slug: contempo-real-estate-core

CVE-2025-2906: Contempo Real Estate Core: Cross-site scripting

Contempo Real Estate Core is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedApr 01, 2025
Safe version guidanceSee mitigation notes
Safe version
Apr 01, 2025 CVE-2025-2906
Contempo Real Estate Core: Cross-site scripting
Contempo Real Estate Core is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending