cleantalk
Vulnerabilities and Security Researches

RealPress – Real Estate Plugin, CVE-2025-11191

CVE, Research URL

CVE-2025-11191

Published on
Oct 31, 2025
Research Description
The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.
Affected versions
max 1.1.0.
Status
vulnerable