Realestateconnected
Realestateconnected Easy Property Listings: vulnerabilidades y CVE
Realestateconnected Easy Property Listings tiene 9 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-16684 | Media (6.4) | 0.33% | — | 1 ago 2026 | The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, 3.5.24 due to insufficient input sanitization and… |
| CVE-2025-68072 | Media (6.5) | 0.32% | — | 22 ene 2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from… |
| CVE-2025-64242 | Media (4.3) | 0.22% | — | 16 dic 2025 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from… |
| CVE-2024-2869 | Media (4.8) | 0.31% | — | 15 may 2025 | The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when… |
| CVE-2024-3163 | Media (4.3) | 0.23% | — | 12 sept 2024 | The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack |
| CVE-2024-32799 | Crítica (9.8) | 0.36% | — | 9 jun 2024 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings.This issue affects Easy Property Listings: from n/a through 3.5.3. |
| CVE-2024-1893 | Alta (8.8) | 0.77% | — | 9 abr 2024 | The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 due to insufficient escaping on the… |
| CVE-2020-5530 | Alta (8.8) | 0.82% | — | 18 feb 2020 | Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors. |
| CVE-2019-15817 | Media (6.1) | 1.00% | — | 30 ago 2019 | The easy-property-listings plugin before 3.4 for WordPress has XSS. |