CVE-2026-13159 PUBLISHED

Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation

Assigner: WPScan
Reserved: 24.06.2026 Published: 06.09.2026 Updated: 06.09.2026

The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate , those are activated as well.

Product Status

Vendor Unknown
Product Real Estate Papi
Versions Default: unknown
  • affected from 0 to 1.0.5 (incl.)

Credits

  • Huynh Kien Minh finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE
  • CWE-352 Cross-Site Request Forgery (CSRF) CWE