RealHomes CRM Plugin Vulnerability Patched
Summary
Hide ▲
Show ▼
A security flaw in the RealHomes CRM plugin, bundled with a WordPress theme, affected over 30,000 websites. The vulnerability allowed low-privileged users to upload malicious files and potentially take control of affected sites. The flaw, assigned CVE-2025-67968, was discovered and reported by Patchstack Alliance community member wackydawg. The developers released a patch in version 1.0.1, which includes access control checks and file validation. The vulnerability was located in an AJAX function responsible for handling CSV file uploads. The flaw allowed any logged-in user with Subscriber-level access or higher to upload arbitrary files, potentially leading to a full site takeover. The patch introduces a current_user_can capability check and file type validation using WordPress's wp_check_filetype function.
Timeline
-
22.01.2026 17:10 1 articles · 23h ago
RealHomes CRM Plugin Vulnerability Patched
A security flaw in the RealHomes CRM plugin, bundled with a WordPress theme, affected over 30,000 websites. The vulnerability allowed low-privileged users to upload malicious files and potentially take control of affected sites. The flaw, assigned CVE-2025-67968, was discovered and reported by Patchstack Alliance community member wackydawg. The developers released a patch in version 1.0.1, which includes access control checks and file validation.
Show sources
- RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites — www.infosecurity-magazine.com — 22.01.2026 17:10
Information Snippets
-
The RealHomes CRM plugin vulnerability affected versions 1.0.0 and earlier.
First reported: 22.01.2026 17:101 source, 1 articleShow sources
- RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites — www.infosecurity-magazine.com — 22.01.2026 17:10
-
The flaw allowed low-privileged users to upload arbitrary files through a CSV import feature.
First reported: 22.01.2026 17:101 source, 1 articleShow sources
- RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites — www.infosecurity-magazine.com — 22.01.2026 17:10
-
The vulnerability was discovered and reported by Patchstack Alliance community member wackydawg.
First reported: 22.01.2026 17:101 source, 1 articleShow sources
- RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites — www.infosecurity-magazine.com — 22.01.2026 17:10
-
The patch in version 1.0.1 introduces a current_user_can capability check and file type validation.
First reported: 22.01.2026 17:101 source, 1 articleShow sources
- RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites — www.infosecurity-magazine.com — 22.01.2026 17:10