
FireStorm Professional Real Estate Plugin Security & Risk Analysis
wordpress.org/plugins/fs-real-estate-pluginThis professional real estate plugin gives you the ability to add real estate listings to your WordPress website.
Is FireStorm Professional Real Estate Plugin Safe to Use in 2026?
Use With Caution
Score 68/100FireStorm Professional Real Estate Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The overall security posture of the fs-real-estate-plugin v2.7.11 shows significant concerns, despite a zero attack surface in terms of direct AJAX handlers, REST API routes, shortcodes, and cron events. However, the code signals reveal deeply rooted security issues. The presence of 'create_function', a known dangerous function, alongside a very low percentage of SQL queries using prepared statements (2%) and output escaping (2%) indicates a high likelihood of vulnerabilities. This is corroborated by the taint analysis, which found 17 high-severity flows with unsanitized paths, suggesting potential for data manipulation and execution of unintended code.
The vulnerability history further solidifies these concerns. With two known CVEs, one of which is critical and currently unpatched, the plugin has a history of SQL injection vulnerabilities. The recent nature of the last vulnerability (2026-01-06) suggests these issues are ongoing. While the plugin exhibits no external HTTP requests and no explicitly identified capability checks or nonce checks on entry points, the core code quality issues related to SQL and output handling, combined with a history of critical vulnerabilities, present a significant risk.
In conclusion, while the plugin does not present a large direct attack surface, the internal code quality is alarmingly poor. The prevalent use of raw SQL queries and insufficient output escaping, coupled with a history of critical unpatched vulnerabilities, makes this plugin a high-risk component. Developers and users should be extremely cautious.
Key Concerns
- Unpatched Critical CVE
- High number of unsanitized taint flows
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- Use of dangerous function: create_function
- No nonce checks found
- No capability checks found
FireStorm Professional Real Estate Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
FireStorm Professional Real Estate <= 2.7.11 - Authenticated (Administrator+) SQL Injection
FireStorm Professional Real Estate Plugin <= 2.06.03 - SQL Injections
FireStorm Professional Real Estate Plugin Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
FireStorm Professional Real Estate Plugin Attack Surface
WordPress Hooks 19
Maintenance & Trust
FireStorm Professional Real Estate Plugin Maintenance & Trust
Maintenance Signals
Community Trust
FireStorm Professional Real Estate Plugin Alternatives
Easy MLS Listings Import
easy-mls-listings-import
Easy MLS Listings Import lets you easily display a real estate agent’s MLS listings. Listings update automatically after set-up for low maintenance!
Featured Property
featured-property-widget
Displays a simple formatted Featured Property as a widget. Perfect way to feature properties that are for sale or rent.
Essential Real Estate
essential-real-estate
Completely plugins Real Estate. Management system which allows you to own and maintain a real estate marketplace, intro website.
Mortgage Calculator
mortgage-calculator
It provides an easy to use mortgage calculator widget.
Houzez WooCommerce Addon
houzez-woo-addon
Houzez WooCommerce addon for Houzez theme only.
FireStorm Professional Real Estate Plugin Developer Profile
2 plugins · 20 total installs
How We Detect FireStorm Professional Real Estate Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fs-real-estate-plugin/css/fsrep_admin_style.css/wp-content/plugins/fs-real-estate-plugin/css/fsrep_frontend.css/wp-content/plugins/fs-real-estate-plugin/css/fsrep_listing_style.css/wp-content/plugins/fs-real-estate-plugin/css/fsrep_widget_style.css/wp-content/plugins/fs-real-estate-plugin/js/fsrep_admin_scripts.js/wp-content/plugins/fs-real-estate-plugin/js/fsrep_frontend_scripts.js/wp-content/plugins/fs-real-estate-plugin/js/fsrep_listing_scripts.js/wp-content/plugins/fs-real-estate-plugin/js/fsrep_widget_scripts.jsfs-real-estate-plugin/css/fsrep_admin_style.css?ver=fs-real-estate-plugin/css/fsrep_frontend.css?ver=fs-real-estate-plugin/css/fsrep_listing_style.css?ver=fs-real-estate-plugin/css/fsrep_widget_style.css?ver=fs-real-estate-plugin/js/fsrep_admin_scripts.js?ver=fs-real-estate-plugin/js/fsrep_frontend_scripts.js?ver=fs-real-estate-plugin/js/fsrep_listing_scripts.js?ver=fs-real-estate-plugin/js/fsrep_widget_scripts.js?ver=HTML / DOM Fingerprints
fsrep_admin_formfsrep_listing_wrapperfsrep_listing_titlefsrep_listing_pricefsrep_listing_imagefsrep_search_formfsrep_widget_container<!-- FireStorm Professional Real Estate Plugin -->data-fsrep-listing-iddata-fsrep-search-noncefsrep_ajax_objectfsrep_frontend_varsfsrep_admin_vars/wp-json/fsrep/v1/listings/wp-json/fsrep/v1/search[fsrep_listings][fsrep_search][fsrep_agent_profile][fsrep_featured_listing]