Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-13318 1 Smartdatasoft 1 Essential Wp Real Estate 2026-04-08 5.3 Medium
The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts.
CVE-2024-12725 1 Smartdatasoft 1 Clasify Classified Listing 2025-06-11 6.1 Medium
The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.