Description

On May 4, 2025, a report was submitted regarding a privilege escalation issue in RealHomes, a widely used WordPress theme with over 33,000 sales. The security flaw allows authenticated users, specifically those with subscriber status or higher, to elevate their own access rights to administrator by altering their user role. Importantly, this vulnerability poses a serious risk only to installations where the “Show user role option in profile” setting is enabled; this feature is not activated by default. A critical security flaw affecting privilege levels has been discovered in the RealHomes WordPress theme, a popular real estate template with over 33,000 sales on ThemeForest. Designated as CVE-2025-4601 and assigned a CVSS score of 8.8, this flaw enables users with minimal permissions to elevate themselves to administrator status, risking full site compromise. Our goal is to enhance the security of the WordPress ecosystem by proactively identifying and mitigating vulnerabilities, which is essential for a robust, multi-layered security framework. Like all privilege escalation vulnerabilities, this flaw can result in a total takeover of the affected site. If an attacker successfully obtains administrative privileges on a WordPress installation, they gain the same capabilities as a legitimate site administrator. This means they can upload plugins or themes, potentially including harmful files with hidden backdoors, as well as alter posts and pages to redirect visitors to unsafe websites or insert unwanted content. It’s important to note again that this security issue is only critically impactful for those who have specifically enabled the “Show user role option in profile” setting. The exploitation process can start with just a subscriber-level account, a role frequently assigned in community-based real estate listing sites, making this vulnerability particularly susceptible to abuse in real-world scenarios. 4.4.1 version, to patch this critical vulnerability. Wordfence strongly recommends that all users update their installations promptly, especially if they have activated the affected setting.