Theme Vulnerability Hub
Theme 4 known issues Latest disclosed Jun 28, 2020

Nexos - Real Estate WordPress Theme Vulnerabilities

Review known vulnerability records for the WordPress theme Nexos - Real Estate WordPress Theme (`nexos`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2020-15364, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
4
High or Critical
2
Patch Coverage
100%
Last Updated
Jan 22, 2024
Priority CVE Quick Links

Fast paths into Nexos - Real Estate WordPress Theme CVE reports

Start with the highest-signal CVE records for this WordPress theme before scanning the full vulnerability feed.

Indexed CVEs
2
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Nexos - Real Estate WordPress Theme so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
4 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
2 critical and 0 high severity findings.
Recent CVEs
CVE-2020-15364
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Nexos - Real Estate WordPress Theme

Sorted by latest disclosure date so newly published issues surface first.

Theme Critical Patched: Yes
Nexos - Real Estate WordPress Theme <= 1.7 - SQL Injection

The Nexos - Real Estate WordPress Theme theme for WordPress is vulnerable to generic SQL Injection via the ‘search_order’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing...

Published
Jun 28, 2020
Patched Release
1.8
Affected Versions
Versions up to 1.7
Next Step
Update to 1.8 or newer if supported.
Theme Medium Patched: Yes
Nexos - Real Estate <= 1.7 - Reflected Cross-Site Scripting

The Nexos - Real Estate theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_location’ parameter in versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...

Published
Jun 28, 2020
Patched Release
1.8
Affected Versions
Versions up to 1.7
Next Step
Update to 1.8 or newer if supported.
Theme Medium Patched: Yes CVE-2020-15364
CVE-2020-15364: Nexos - Real Estate WordPress Theme < 1.8 - Cross-Site Scripting

The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.

Published
Jun 17, 2020
Patched Release
1.8
Affected Versions
Versions before 1.8
Next Step
Update to 1.8 or newer if supported.
Theme Critical Patched: Yes CVE-2020-15363
CVE-2020-15363: Nexos - Real Estate WordPress Theme <= 1.7 - SQL Injection

The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.

Published
Jun 17, 2020
Patched Release
1.8
Affected Versions
Versions before 1.8
Next Step
Update to 1.8 or newer if supported.