Realestateconnected's vulnerability footprint centers on its Easy Property Listings web application, where disclosures skew toward serious outcomes with a meaningful share reaching critical severity. The recurring exposure reflects classic web-application weaknesses: cross-site request forgery, cross-site scripting, SQL injection, and missing authorization controls that are characteristic of business-logic and data-handling layers in property-management platforms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Realestateconnected over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-32799CRITICAL Missing Authorization vulnerability in Merv Barrett Easy Property Listings.This issue affects Easy Property Listings: from n/a through 3.5.3. | Jun 9, 2024 | 9.8 | 26 | NO | NO |
CVE-2020-5530HIGH Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecifi | Feb 18, 2020 | 8.8 | 26 | NO | NO |
CVE-2024-1893HIGH The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 | Apr 9, 2024 | 8.8 | 25 | NO | NO |
CVE-2019-15817MEDIUM The easy-property-listings plugin before 3.4 for WordPress has XSS. | Aug 30, 2019 | 6.1 | 21 | NO | NO |
CVE-2024-2869MEDIUM The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C | May 15, 2025 | 4.8 | 16 | NO | NO |
CVE-2024-3163MEDIUM The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them | Sep 12, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Realestateconnected.
Media articles that mention a CVE ID that affects a product developed by Realestateconnected — matched by CVE ID, not by vendor name.