AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15142

HIGH · CVSS 7.5

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Real Estate Manager Pro plugin for WordPress is vulnerable to privilege escalation due to improper capability handling in the allow_attachment_actions() function, affecting all versions up to 12.8.6. This flaw allows authenticated attackers with at least Subscriber-level access to edit an administrator account if the target user ID corresponds to an existing media attachment ID. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of unauthorized privilege escalation.

CVE
CVE-2026-15142
Severity
HIGH
CVSS
7.5
EPSS
N/A
WordPress

Original NVD Description

The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID during user capability checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit an administrator account and escalate their privileges to Administrator when the targeted user ID matches the ID of an existing media attachment.