๐Ÿ” CVE Alert

CVE-2021-4388

MEDIUM 4.3

Opal Estate <= 1.6.11 - Missing Authorization

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers to set and remove featured properties.

CWE CWE-862
Vendor wpopal
Product opal estate
Published Jul 1, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for wpopal opal estate

Be the first to know when new medium vulnerabilities affecting wpopal opal estate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

wpopal / Opal Estate
0 โ‰ค 1.6.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/5ce729a2-a106-45ab-b96c-cfe75246def7?source=cve blog.nintechnet.com: https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-5/ plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/opal-estate/trunk/inc/ajax-functions.php#L177

Credits

Jerome Bruandet