WordPress security by component
Real Estate Papi
Real Estate Papi (real-estate-papi) is a WordPress theme with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 06, 2026; the highest published CVSS base score is 4.3.
Theme slug:
real-estate-papiLatest vulnerability
CVE-2026-13159: Real Estate Papi permits Subscriber-level companion-plugin installation
Real Estate Papi through 1.0.5 omits capability and CSRF checks from an AJAX action that installs a fixed set of companion plugins from WordPress.org. Any authenticated user, including a Subscriber, can trigger installation; if the request runs in a session permitted to activate plugins, the installed companions are activated as well.
| Safe version |
|
||
|---|---|---|---|
| Sep 06, 2026 |
CVE-2026-13159
Real Estate Papi permits Subscriber-level companion-plugin installation
Real Estate Papi through 1.0.5 omits capability and CSRF checks from an AJAX action that installs a fixed set of companion plugins from WordPress.org. Any authenticated user, including a Subscriber, can trigger installation; if the request runs in a session permitted to activate plugins, the installed companions are activated as well.
|
See mitigation notes |
CVE4.3
NVDPending
|