SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13159

MEDIUM · CVSS 4.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Real Estate Papi WordPress theme versions up to 1.0.5 are vulnerable due to inadequate capability and CSRF checks on specific AJAX actions, enabling any authenticated user to install and activate a predetermined set of plugins from the WordPress.org repository. This flaw could lead to unauthorized plugin activation, potentially compromising site security and functionality. WordPress site administrators using this theme should prioritize applying updates to mitigate this risk.

CVE
CVE-2026-13159
Severity
MEDIUM
CVSS
4.3
EPSS
0.10%
WordPress

Original NVD Description

The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate , those are activated as well.