CyberRota Analysis
AI-GeneratedThe Real Estate Papi WordPress theme versions up to 1.0.5 are vulnerable due to inadequate capability and CSRF checks on specific AJAX actions, enabling any authenticated user to install and activate a predetermined set of plugins from the WordPress.org repository. This flaw could lead to unauthorized plugin activation, potentially compromising site security and functionality. WordPress site administrators using this theme should prioritize applying updates to mitigate this risk.
Original NVD Description
The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate , those are activated as well.