G5plus maintains a small portfolio of web-based real-estate and WordPress plugin products, including Essential Real Estate, Ultimate Bootstrap Elements for Elementor, and several theme and plugin offerings that serve content management and property-listing use cases. Despite the narrow product count, the vendor's disclosures are more prominent than many others in the landscape, reflecting the broad deployment of WordPress ecosystem extensions and the accessibility of these web-facing applications to attackers. Vulnerabilities affecting this vendor skew toward serious outcomes, concentrating in a recurring pattern of input-handling and file-management weaknesses: cross-site scripting flaws, path traversal, unrestricted file uploads, and exposure of sensitive information, all of which are endemic to web applications with user-supplied content and inadequate validation boundaries. These weakness classes represent straightforward attack vectors against web-facing plugins and themes, making defenders' patching of this vendor's releases important for WordPress installations relying on these products. Current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by G5plus over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48126CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows | Jun 9, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-13545CRITICAL The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unau | Jan 24, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-30849CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows | Apr 1, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-24797CRITICAL Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: | Feb 12, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-13418HIGH Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This | May 2, 2025 | 8.8 | 25 | NO | NO |
CVE-2023-6140HIGH The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files | Jan 8, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-37462HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows Path Traversal.This issue a | Jul 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-6827HIGH The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFonts' function in versions up to, | Dec 15, 2023 | 8.8 | 23 | NO | NO |
CVE-2024-43140HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows PHP Local File Inclusion.Th | Aug 13, 2024 | 8.8 | 22 | NO | NO |
CVE-2023-6139MEDIUM The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber acc | Jan 8, 2024 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by G5plus.
Media articles that mention a CVE ID that affects a product developed by G5plus — matched by CVE ID, not by vendor name.