CVE-2026-13159
Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate , those are activated as well.
| Vendor | unknown |
| Product | real estate papi |
| Published | Sep 6, 2026 |
| Last Updated | Sep 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown real estate papi
Be the first to know when new medium vulnerabilities affecting unknown real estate papi are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Real Estate Papi
0 โค 1.0.5
References
Credits
Huynh Kien Minh WPScan