Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

G5plus

First CVE: Dec 15, 2023Active for: 3 yearsTotal CVEs: 20
22.4
VTI Score
Low

G5plus maintains a small portfolio of web-based real-estate and WordPress plugin products, including Essential Real Estate, Ultimate Bootstrap Elements for Elementor, and several theme and plugin offerings that serve content management and property-listing use cases. Despite the narrow product count, the vendor's disclosures are more prominent than many others in the landscape, reflecting the broad deployment of WordPress ecosystem extensions and the accessibility of these web-facing applications to attackers. Vulnerabilities affecting this vendor skew toward serious outcomes, concentrating in a recurring pattern of input-handling and file-management weaknesses: cross-site scripting flaws, path traversal, unrestricted file uploads, and exposure of sensitive information, all of which are endemic to web applications with user-supplied content and inadequate validation boundaries. These weakness classes represent straightforward attack vectors against web-facing plugins and themes, making defenders' patching of this vendor's releases important for WordPress installations relying on these products. Current severity and exploitation status are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by G5plus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2023
2 years ago
Most Recent CVE
Jun 9, 2025
410 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-48126CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows
Jun 9, 20259.830NONO
CVE-2024-13545CRITICAL
The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unau
Jan 24, 20259.829NONO
CVE-2025-30849CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows
Apr 1, 20259.827NONO
CVE-2024-24797CRITICAL
Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On:
Feb 12, 20249.827NONO
CVE-2024-13418HIGH
Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This
May 2, 20258.825NONO
CVE-2023-6140HIGH
The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files
Jan 8, 20248.825NONO
CVE-2024-37462HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows Path Traversal.This issue a
Jul 9, 20248.824NONO
CVE-2023-6827HIGH
The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFonts' function in versions up to,
Dec 15, 20238.823NONO
CVE-2024-43140HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows PHP Local File Inclusion.Th
Aug 13, 20248.822NONO
CVE-2023-6139MEDIUM
The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber acc
Jan 8, 20246.522NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
55%
25%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (75.0%)
Unknown0 (0.0%)
Required5 (25.0%)
Privileges Required
Low15 (75.0%)
High0 (0.0%)
None5 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by G5plus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by G5plus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For G5plus's Products

View all 3 CNAs →

Top CWEs