PatchSiren cyber security CVE debrief
CVE-2026-15142 WebCodingPlace CVE debrief
The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID during user capability checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit an administrator account and escalate their privileges to Administrator when the targeted user ID matches the ID of an existing media attachment.
- Vendor
- WebCodingPlace
- Product
- Real Estate Manager Pro
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
WordPress users with the Real Estate Manager Pro plugin installed, particularly those with Subscriber-level access and above, should verify and apply patches to prevent potential privilege escalation attacks. Additionally, security teams and vulnerability management teams should review the affected plugin versions and assess their exposure to this vulnerability. Operators of WordPress platforms and security administrators should prioritize patching and implement compensating controls to mitigate potential attacks. Those responsible for monitoring and incident response should be aware of the vulnerability's impact and prepare for potential exploitation attempts.
Technical summary
The vulnerability is caused by improper capability handling in the allow_attachment_actions() function, allowing authenticated attackers with Subscriber-level access to edit administrator accounts and escalate privileges. This occurs when the targeted user ID matches the ID of an existing media attachment. The issue affects all versions of the Real Estate Manager Pro plugin up to, and including, 12.8.6. To exploit this vulnerability, attackers must have Subscriber-level access or higher. The vulnerability's technical impact is significant, as it enables attackers to gain elevated privileges and potentially control the affected system.
Defensive priority
Authenticated attackers with Subscriber-level access can potentially escalate privileges by editing administrator accounts.
Recommended defensive actions
- Inventory and verify installed plugin versions.
- Apply vendor patches or updates.
- Monitor for suspicious administrator account activity.
- Restrict Subscriber-level access and above.
- Implement compensating controls for privilege escalation.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the source detail is limited, and further verification is needed to confirm the affected scope and vendor remediation. Additional review of plugin versions, user access controls, and media attachment handling is required to assess the vulnerability's impact. Defenders should verify plugin installations, user roles, and media management practices to identify potential exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15142 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15142
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15142 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15142
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wp-rem.com/changelog/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.