
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68071 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the Essential Real Estate WordPress plugin developed by g5theme. It allows authenticated attackers with low privileges (e.g., ERE Customer role) to bypass access controls and access sensitive data. The vulnerability affects Essential Real Estate versions up to and including 5.3.2, with the CVE record updated multiple times to reflect an expanding affected version range (initially reported as ≤ 5.2.2, then ≤ 5.2.9, and finally ≤ 5.3.2). It was reported by researcher "daroo" on November 14, 2025, and published by Patchstack on December 16, 2025. The CVSS v3.1 base score is 6.5 (Medium), assigned by both Patchstack and CISA-ADP (Patchstack, NVD).
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), a form of Insecure Direct Object Reference (IDOR) mapped to OWASP Top 10 A1: Broken Access Control. The root cause is that the plugin fails to properly validate whether an authenticated user is authorized to access objects (such as listings, documents, or user data) referenced by user-supplied keys or identifiers in requests. An attacker with a low-privilege account (e.g., an ERE Customer) can manipulate object reference parameters in network requests to access resources belonging to other users without proper authorization checks. No public proof-of-concept exploit code has been identified at this time (Patchstack, NVD).
Successful exploitation results in unauthorized access to sensitive information managed by the Essential Real Estate plugin, such as property listings, customer data, or other plugin-managed records, representing a high confidentiality impact. There is no integrity or availability impact identified. The attack is network-based, requires no user interaction, and only low-level authentication (a registered ERE Customer account), making it accessible to a broad range of potential attackers on affected WordPress sites (Patchstack, NVD).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-68071. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority, noting it is unlikely to be exploited despite the potential for use in mass-exploit campaigns targeting WordPress plugins (Patchstack, NVD).
?listing_id=1, ?listing_id=2, etc.) in a short time period.As of the time of reporting, no official patch was available for CVE-2025-68071; the Patchstack advisory notes "No official patch available" for versions ≤ 5.3.3. Site administrators should monitor the g5theme Essential Real Estate plugin's official WordPress repository and the developer's release notes for a patched version and apply it immediately upon release. In the interim, consider disabling the plugin if it is not critical to site operations, restricting user registration to prevent untrusted users from obtaining ERE Customer accounts, or deploying a Web Application Firewall (WAF) with virtual patching capabilities such as Patchstack to block exploitation attempts (Patchstack).
The vulnerability was discovered and disclosed by Patchstack researcher "daroo" and received standard automated coverage from vulnerability aggregators and security feeds. No notable vendor statements, high-profile researcher commentary, or significant media coverage beyond routine CVE publication has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."