What is CVE-2026-15142?
CVE-2026-15142 is a Privilege Escalation vulnerability in the Real Estate Manager Pro plugin for WordPress, affecting all versions up to 12.8.6. The flaw stems from improper capability handling in the allow_attachment_actions() function, allowing an authenticated user to escalate their privileges. Users are advised to disable the plugin until a security patch is released.
Azərbaycanca: CVE-2026-15142, WordPress-in Real Estate Manager Pro plaginin 12.8.6 daxil olmaqla bütün versiyalarına təsir edən imtiyaz yüksəltmə (Privilege Escalation) zəifliyidir. allow_attachment_actions() funksiyasındakı düzgün olmayan capability yoxlaması səbəbindən autentifikasiya olunmuş istifadəçi daha yüksək səlahiyyətlər əldə edə bilər. Plagin tərtibatçısı təhlükəsizlik yeniləməsini buraxana qədər plaqini deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which WordPress plugin is affected by CVE-2026-15142?
CVE-2026-15142 affects the Real Estate Manager Pro plugin.
What is recommended for users to do until a security patch is released?
Users are advised to disable the plugin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.