The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts.
The accidental deletion of a data-structure sentinel can cause serious programming logic problems.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Essential_wp_real_estate | Smartdatasoft | * | 1.1.3 (including) |