RealHomes CRM 1.0.1 security patch (CVE-2025-67968)
Security Patch Release
Summary
Hide ▲
Show ▼
Developers released RealHomes CRM 1.0.1 to fix CVE-2025-67968, a file-upload flaw affecting versions 1.0.0 and earlier on WordPress sites. The bug let Subscriber-level users upload arbitrary files through a CSV import path, creating a route to malicious code upload and possible site takeover. The patch adds a current_user_can check and wp_check_filetype validation to restrict who can upload and what can be uploaded.
Related Happenings
Adobe PolyShell fix for Magento Open Source and Adobe Commerce
Security Patch Release
H score21
First: 19.03.2026 22:01
Last: 19.03.2026 22:01
Sources 1
About this happening:
Adobe released an alpha fix for PolyShell, but production Magento Open Source and Adobe Commerce stable version 2 installations remain vulnerable. The update is only p...
Adobe PolyShell fix for Magento Open Source and Adobe Commerce
Security Patch ReleaseAbout this happening: Adobe released an alpha fix for PolyShell, but production Magento Open Source and Adobe Commerce stable version 2 installations remain vulnerable. The update is only p...
WPvivid Backup & Migration plugin security update 0.9.124 (CVE-2026-1357)
Security Patch Release
H score21
First: 12.02.2026 19:09
Last: 12.02.2026 19:09
Sources 1
About this happening:
WPVividPlugins released version 0.9.124 on January 28 to fix CVE-2026-1357 in the WPvivid Backup & Migration plugin for WordPress. The patch closes a critica...
WPvivid Backup & Migration plugin security update 0.9.124 (CVE-2026-1357)
Security Patch ReleaseAbout this happening: WPVividPlugins released version 0.9.124 on January 28 to fix CVE-2026-1357 in the WPvivid Backup & Migration plugin for WordPress. The patch closes a critica...
Cisco Unified Communications and Webex Calling patch release for CVE-2026-20045
Security Patch Release
H score40
First: 22.01.2026 00:16
Last: 22.01.2026 00:16
Sources 1
About this happening:
Cisco released version-specific updates and patch files for CVE-2026-20045, a critical remote code execution flaw affecting Unified CM, SME, IM & Presenc...
Cisco Unified Communications and Webex Calling patch release for CVE-2026-20045
Security Patch ReleaseAbout this happening: Cisco released version-specific updates and patch files for CVE-2026-20045, a critical remote code execution flaw affecting Unified CM, SME, IM & Presenc...
GitLab security patch release for CVE-2026-0723
Security Patch Release
H score71
First: 21.01.2026 15:57
Last: 21.01.2026 15:57
Sources 1
About this happening:
GitLab released 18.8.2, 18.7.2, and 18.6.4 to fix multiple security flaws in GitLab CE/EE. The update matters because one of the issues, CVE-2026-0723, is a high-s...
GitLab security patch release for CVE-2026-0723
Security Patch ReleaseAbout this happening: GitLab released 18.8.2, 18.7.2, and 18.6.4 to fix multiple security flaws in GitLab CE/EE. The update matters because one of the issues, CVE-2026-0723, is a high-s...
Chainlit security patch release for CVE-2026-22218
Security Patch Release
H score34
First: 21.01.2026 11:10
Last: 21.01.2026 11:10
Sources 1
About this happening:
Chainlit released version 2.9.4 to fix CVE-2026-22218 and CVE-2026-22219, closing flaws that could expose API keys, sensitive files, and internal metadat...
Chainlit security patch release for CVE-2026-22218
Security Patch ReleaseAbout this happening: Chainlit released version 2.9.4 to fix CVE-2026-22218 and CVE-2026-22219, closing flaws that could expose API keys, sensitive files, and internal metadat...
Timeline
-
22.01.2026 17:10 1 articles · 5mo ago
RealHomes CRM CVE-2025-67968 file-upload flaw disclosed
Technical Analysis UpdateResearchers identified CVE-2025-67968 in RealHomes CRM versions 1.0.0 and earlier, where logged-in Subscriber-level users or higher could upload arbitrary files through a CSV import feature because the AJAX upload handler lacked privilege checks and file-type validation, creating a path to malicious code upload and full site takeover on WordPress sites using the RealHomes theme.
Show sources
- RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites — www.infosecurity-magazine.com — 22.01.2026 17:10
-
22.01.2026 17:10 2 articles · 5mo ago
RealHomes CRM 1.0.1 release adds upload controls
Mitigation Patch UpdateIn response to CVE-2025-67968, InspiryThemes released RealHomes CRM 1.0.1 with a current_user_can capability check and wp_check_filetype validation so only authorised users can access the upload feature and only permitted file types and extensions can be written to the server.
Show sources
- RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites — www.infosecurity-magazine.com — 22.01.2026 17:10
- RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites — www.infosecurity-magazine.com — 22.01.2026 17:10