CVE-2023-6139medium

CVE-2023-6139: medium-severity vulnerability in Essential Real Estate

Essential Real Estate < 4.4.0 - Subscriber+ Denial of Service via Arbitrary Option Update

Published · Updated

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H