FireStorm Professional Real Estate Plugin Security & Risk Analysis

wordpress.org/plugins/fs-real-estate-plugin

This professional real estate plugin gives you the ability to add real estate listings to your WordPress website.

10 active installs v2.7.11 PHP + WP 3.6+ Updated Unknown
homehousereal-estaterealtorrealty
68
C · Use Caution
CVEs total2
Unpatched1
Last CVEJan 6, 2026
Safety Verdict

Is FireStorm Professional Real Estate Plugin Safe to Use in 2026?

Use With Caution

Score 68/100

FireStorm Professional Real Estate Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

2 known CVEs 1 unpatched Last CVE: Jan 6, 2026
Risk Assessment

The overall security posture of the fs-real-estate-plugin v2.7.11 shows significant concerns, despite a zero attack surface in terms of direct AJAX handlers, REST API routes, shortcodes, and cron events. However, the code signals reveal deeply rooted security issues. The presence of 'create_function', a known dangerous function, alongside a very low percentage of SQL queries using prepared statements (2%) and output escaping (2%) indicates a high likelihood of vulnerabilities. This is corroborated by the taint analysis, which found 17 high-severity flows with unsanitized paths, suggesting potential for data manipulation and execution of unintended code.

The vulnerability history further solidifies these concerns. With two known CVEs, one of which is critical and currently unpatched, the plugin has a history of SQL injection vulnerabilities. The recent nature of the last vulnerability (2026-01-06) suggests these issues are ongoing. While the plugin exhibits no external HTTP requests and no explicitly identified capability checks or nonce checks on entry points, the core code quality issues related to SQL and output handling, combined with a history of critical vulnerabilities, present a significant risk.

In conclusion, while the plugin does not present a large direct attack surface, the internal code quality is alarmingly poor. The prevalent use of raw SQL queries and insufficient output escaping, coupled with a history of critical unpatched vulnerabilities, makes this plugin a high-risk component. Developers and users should be extremely cautious.

Key Concerns

  • Unpatched Critical CVE
  • High number of unsanitized taint flows
  • Low percentage of prepared SQL statements
  • Low percentage of properly escaped output
  • Use of dangerous function: create_function
  • No nonce checks found
  • No capability checks found
Vulnerabilities
2

FireStorm Professional Real Estate Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2012
2012
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
1

2 total CVEs

CVE-2026-22470medium · 4.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

FireStorm Professional Real Estate <= 2.7.11 - Authenticated (Administrator+) SQL Injection

Jan 6, 2026Unpatched
WF-854e5d70-f42f-48c4-b1bb-687610f86cfb-fs-real-estate-plugincritical · 9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

FireStorm Professional Real Estate Plugin <= 2.06.03 - SQL Injections

Oct 25, 2012 Patched in 2.06.04 (4107d)
Code Analysis
Analyzed Mar 16, 2026

FireStorm Professional Real Estate Plugin Code Analysis

Dangerous Functions
2
Raw SQL Queries
253
6 prepared
Unescaped Output
293
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
48
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action( 'widgets_init', create_function( '', 'register_widget("FSREP_Location_Widget");' ) );widget_local.php:79
create_functionadd_action( 'widgets_init', create_function( '', 'register_widget("FSREP_Search_Widget");' ) );widget_search.php:48

SQL Query Safety

2% prepared259 total queries

Output Escaping

2% escaped300 total outputs
Data Flows
19 unsanitized

Data Flow Analysis

19 flows19 with unsanitized paths
fsrep_listing_manager (common_functions.php:904)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FireStorm Professional Real Estate Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionadmin_noticescommon_functions.php:41
actionsave_postdefine.php:40
actioninitdefine.php:41
actionadmin_noticesdefine.php:254
actionadmin_noticesdefine.php:265
filterwp_footerdefine.php:273
actionadmin_noticesdefine.php:286
actionadmin_noticesdefine.php:295
actionadmin_noticesdefine.php:336
filterthe_contentfilters.php:3
filterwp_titlefilters.php:4
actionadmin_menuhooks.php:2
actionadmin_bar_menuhooks.php:29
actionwp_headhooks.php:120
actionadmin_headhooks.php:391
actionadmin_initincludes\admin_listings.php:2
filterwp_mail_content_typeincludes\listing_contact_form.php:18
actionwidgets_initwidget_local.php:79
actionwidgets_initwidget_search.php:48
Maintenance & Trust

FireStorm Professional Real Estate Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedUnknown
PHP min version
Downloads44K

Community Trust

Rating58/100
Number of ratings43
Active installs10
Developer Profile

FireStorm Professional Real Estate Plugin Developer Profile

FireStorm Plugins

2 plugins · 20 total installs

55
trust score
Avg Security Score
66/100
Avg Patch Time
4107 days
View full developer profile
Detection Fingerprints

How We Detect FireStorm Professional Real Estate Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fs-real-estate-plugin/css/fsrep_admin_style.css/wp-content/plugins/fs-real-estate-plugin/css/fsrep_frontend.css/wp-content/plugins/fs-real-estate-plugin/css/fsrep_listing_style.css/wp-content/plugins/fs-real-estate-plugin/css/fsrep_widget_style.css/wp-content/plugins/fs-real-estate-plugin/js/fsrep_admin_scripts.js/wp-content/plugins/fs-real-estate-plugin/js/fsrep_frontend_scripts.js/wp-content/plugins/fs-real-estate-plugin/js/fsrep_listing_scripts.js/wp-content/plugins/fs-real-estate-plugin/js/fsrep_widget_scripts.js
Version Parameters
fs-real-estate-plugin/css/fsrep_admin_style.css?ver=fs-real-estate-plugin/css/fsrep_frontend.css?ver=fs-real-estate-plugin/css/fsrep_listing_style.css?ver=fs-real-estate-plugin/css/fsrep_widget_style.css?ver=fs-real-estate-plugin/js/fsrep_admin_scripts.js?ver=fs-real-estate-plugin/js/fsrep_frontend_scripts.js?ver=fs-real-estate-plugin/js/fsrep_listing_scripts.js?ver=fs-real-estate-plugin/js/fsrep_widget_scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
fsrep_admin_formfsrep_listing_wrapperfsrep_listing_titlefsrep_listing_pricefsrep_listing_imagefsrep_search_formfsrep_widget_container
HTML Comments
<!-- FireStorm Professional Real Estate Plugin -->
Data Attributes
data-fsrep-listing-iddata-fsrep-search-nonce
JS Globals
fsrep_ajax_objectfsrep_frontend_varsfsrep_admin_vars
REST Endpoints
/wp-json/fsrep/v1/listings/wp-json/fsrep/v1/search
Shortcode Output
[fsrep_listings][fsrep_search][fsrep_agent_profile][fsrep_featured_listing]
FAQ

Frequently Asked Questions about FireStorm Professional Real Estate Plugin