CVE-2025-3610 Details
Description
The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's passwords and email addresses, including administrators, and leverage that to gain access to their account. This can be combined with CVE-2025-3609 to achieve remote code execution as an originally unauthenticated user with no account.
A privilege escalation vulnerability allowing account takeover has been identified in the Reales WP STPT plugin for WordPress, affecting all versions through 2.1.2. The issue arises because the plugin fails to properly validate a user's identity before allowing updates to account details such as passwords and email addresses. This flaw enables authenticated attackers with subscriber-level access or higher to change the passwords and email addresses of any user, including administrators, thereby gaining unauthorized access to their accounts. Furthermore, this vulnerability can be exploited in conjunction with CVE-2025-3609 to achieve remote code execution as an initially unauthenticated user without an account.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 6, 2025CISA-ADP
Assessed May 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://themeforest.net/item/reales-wp-real-estate-wordpress-theme/10330568 | [email protected] | Broken LinkProductVendor |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/38c6b149-39d7-491a-9f3a-261087a52a03?source=cve | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Reales WP STPT | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2025 | New CVE Received | [email protected] |
Volerion