CVE-2025-48126: WordPress Essential Real Estate plugin <= 5.3.2 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows PHP Local File Inclusion.This issue affects Essential Real Estate: from n/a through <= 5.2.9.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows PHP Local File Inclusion.This issue affects Essential Real Estate: from n/a through <= 5.3.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48126?
CVE-2025-48126 is rated as a critical severity vulnerability due to the potential for remote file inclusion attacks.
How do I fix CVE-2025-48126?
To fix CVE-2025-48126, update the Essential Real Estate plugin to the latest version beyond 5.2.2.
What is the main impact of CVE-2025-48126?
The main impact of CVE-2025-48126 is the possibility of an attacker executing arbitrary PHP code on the server through local file inclusion.
Which versions of Essential Real Estate are affected by CVE-2025-48126?
CVE-2025-48126 affects Essential Real Estate versions from n/a through 5.2.1.
Is there a public exploit available for CVE-2025-48126?
As of now, there is no known public exploit for CVE-2025-48126, but the vulnerability is serious enough to warrant immediate attention.