CVE-2025-1285
Description
The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api_key and save_api_key AJAX actions in all versions up to, and including, 3.6. This makes it possible for unauthenticated attackers to issue requests to internal services and update API key details.
CWE
- CWE-862 — CWE-862 Missing Authorization
Affected
- SmartDataSoft / Resido - Real Estate WordPress Theme — v=0 ≤3.6 [affected]
CVSS
- 3.1 score=5.3 severity=MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3512ce8f-b7a6-4a6f-a141-bca08c183882?source=cve
- https://themeforest.net/item/resido-real-estate-wordpress-theme/31804443
Source
cvelistV5-main/cves/2025/1xxx/CVE-2025-1285.json