CVE-2025-39459General

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Incorrect Privilege Assignment vulnerability in contempoinc Real Estate 7 realestate-7 allows Privilege Escalation.This issue affects Real Estate 7: from n/a through <= 3.5.2.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-03)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-27: 1Mentions · 2026-03-03: 2PoC Mentioned / Linked · 2026-02-27: 1Exploit Tool / Code · 2026-02-27: 1Technical Details · 2026-02-27: 102-2703-03
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-271
Disclosure1
2026-03-032
General2
Full discourse3 posts
  • Nxploited@Nxploited
    Disclosure

    CVE-2025-39459 | Real Estate 7 (WordPress theme) Unauthenticated Privilege Escalation (Admin) CVSS 9.8 (Critical) PoC: https://github.com/Nxploited/CVE-2025-39459 #CVE #CVE2025 #WordPress #WPTheme #Vulnerability #InfoSec #CyberSecurity #Pentest #BugBounty #Exploit #PoC #AppSec

    Post summary

    A critical unauth privilege escalation vulnerability (CVSS 9.8) in the Real Estate 7 WordPress theme has been disclosed, with PoC code available on GitHub.

    00121174
    91 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: Exploit for CVE-2025-39459 Intel Report: https://ift.tt/aeOh1my

    Post summary

    The alert references a possible exploit for CVE-2025-39459 and provides a link to an Intel report but lacks detailed technical, PoC, patch, or active exploitation information.

    0000079
    342 followersView on X
  • Md Shoriful Islam@RootHarpy
    General

    Nuclei template for CVE-2025-39459! Ready to tackle security challenges ahead! Repository: https://github.com/RootHarpy/CVE-2025-39459-Nuclei-Template

    Post summary

    A GitHub repository hosts a Nuclei template for CVE-2025-39459, but no additional details on the vulnerability or exploitation are provided.

    0000085
    3 followersView on X

Explore more