๐Ÿ” CVE Alert

CVE-2026-15142

HIGH 7.5

Real Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID during user capability checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit an administrator account and escalate their privileges to Administrator when the targeted user ID matches the ID of an existing media attachment.

CWE CWE-269
Vendor webcodingplace
Product real estate manager pro
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for webcodingplace real estate manager pro

Be the first to know when new high vulnerabilities affecting webcodingplace real estate manager pro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

WebCodingPlace / Real Estate Manager Pro
0 โ‰ค 12.8.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/71e9ff91-4137-4c66-959b-f4ffb8d3ba32?source=cve wp-rem.com: https://wp-rem.com/changelog/

Credits

0xd4rk5id3