The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID during user capability checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edi [truncated]
A Cross-site Scripting vulnerability was found in Real Estate Manager Pro, a WordPress plugin. This issue allows for Reflected XSS attacks, potentially enabling attackers to inject malicious scripts into web pages viewed by users of the plugin. The CVE record was published on 2026-07-13T10:16:33.340Z and has not been modified since then. Administrators and users should be aware of this vulnerability and t [truncated]