Inspirythemes develops real-estate and property-management WordPress themes and plugins, with a narrow but operationally important scope as these products directly integrate with website access controls and user role management. The recurring vulnerability signal centers on privilege and authorization weaknesses—specifically incorrect privilege assignment and missing authorization checks—reflecting the complexity of managing multi-user property listing and client access in WordPress-based platforms. Current CVE, severity, and exploitation status are shown in the live panel alongside this summary.
The number and severity of CVEs published that impact products developed by Inspirythemes over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-32444CRITICAL Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.3.6. | Sep 3, 2025 | 9.8 | 35 | NO | NO |
CVE-2026-56055HIGH Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions. | Jun 26, 2026 | 8.8 | 33 | NO | NO |
CVE-2025-49867CRITICAL Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.4.0. | Jul 4, 2025 | 9.8 | 28 | NO | NO |
CVE-2023-37886HIGH Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2. | Mar 25, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-37885HIGH Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2. | Mar 25, 2024 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inspirythemes.
Media articles that mention a CVE ID that affects a product developed by Inspirythemes — matched by CVE ID, not by vendor name.