CVE-2026-13159
Received Received - Intake

Real Estate Papi Theme Plugin Installation via AJAX

Vulnerability report for CVE-2026-13159, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-06

Last updated on: 2026-09-06

Assigner: WPScan

Description

The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate , those are activated as well.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-06
Last Modified
2026-09-06
Generated
2026-09-06
AI Q&A
2026-09-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
real_estate_papi real_estate_papi to 1.0.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Real Estate Papi WordPress theme up to version 1.0.5 has a vulnerability where it fails to check user capabilities or CSRF tokens for an AJAX action. This allows any authenticated user, including low-privilege subscribers, to install a fixed set of companion plugins from WordPress.org. If the user can activate plugins, the installed plugins are activated automatically.

Detection Guidance

Check WordPress installations for the Real Estate Papi theme version 1.0.5 or earlier. Review server logs for unauthorized plugin installations or activations by low-privilege users like subscribers. Use WPScan to scan for vulnerable themes with: wpscan --url <target_url> --enumerate vp,vt.

Impact Analysis

An attacker with subscriber-level access could exploit this to install and activate unwanted plugins on your WordPress site. This could lead to malicious code execution, unauthorized access, or further compromise of your site and data.

Compliance Impact

This vulnerability could lead to unauthorized plugin installations, potentially introducing data breaches or malware. Such incidents may violate GDPR (data protection) or HIPAA (health data security) by exposing sensitive user data or failing to maintain system integrity.

Mitigation Strategies

Update the Real Estate Papi theme to the latest version immediately. Remove or disable the theme if no update is available. Restrict plugin installation permissions to administrators only. Monitor for unauthorized plugin activations and review user roles for excessive privileges.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13159. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart