CVE-2025-8218
BaseFortify
Publication date: 2025-08-19
Last updated on: 2025-08-19
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| real_spaces | wordpress_properties_directory_theme | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Real Spaces - WordPress Properties Directory Theme up to version 3.5. It allows unauthenticated attackers to escalate their privileges by exploiting the 'change_role_member' parameter during a profile update. Due to insufficient restrictions, attackers can arbitrarily assign themselves any role, including the Administrator role.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can gain administrator-level access to the affected WordPress site without authentication. This can lead to full control over the site, including modifying content, installing malicious code, stealing data, or disrupting services.