Immocaster WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/immocaster

Das Wordpress Plugin von Immocaster ermöglicht die Anzeige von Immobilien von ImmobilienScout24 im eingehen Blog.

10 active installs v1.3.6 PHP + WP 3.7+ Updated Sep 30, 2015
estateestatesimmobilieimmobilienreal-estates
61
C · Use Caution
CVEs total1
Unpatched1
Last CVEJul 28, 2025
Safety Verdict

Is Immocaster WordPress Plugin Safe to Use in 2026?

Use With Caution

Score 61/100

Immocaster WordPress Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jul 28, 2025Updated 10yr ago
Risk Assessment

The immocaster v1.3.6 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce checks. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is also a strong indicator of a reduced attack surface. However, the static analysis reveals significant concerns, most notably that only 9% of its 81 outputs are properly escaped, leaving a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the presence of two unsanitized taint flows, though not classified as critical or high severity in this analysis, warrants further investigation as these can often lead to exploitable conditions. The vulnerability history is a major red flag, with one high-severity "PHP Remote File Inclusion" vulnerability that is currently unpatched. This historical pattern of severe vulnerabilities, especially the recurring RFI type, suggests a recurring weakness in how external data or files are handled within the plugin.

While the plugin has strengths in its minimal attack surface and SQL query handling, the critical issues of poor output escaping and a recent, unpatched RFI vulnerability present a substantial risk. The historical pattern of RFI vulnerabilities is particularly concerning, as it indicates a persistent flaw that could be exploited again. Therefore, users of immocaster v1.3.6 should exercise extreme caution. The unpatched RFI vulnerability alone is a critical risk that needs immediate attention, and the widespread lack of output escaping increases the overall exposure to other common web vulnerabilities.

Key Concerns

  • Unpatched high severity CVE
  • Low output escaping percentage (9%)
  • Unsanitized taint flows (2)
Vulnerabilities
1

Immocaster WordPress Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-60190high · 8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Immocaster WordPress <= 1.3.6 - Unauthenticated Local File Inclusion

Jul 28, 2025Unpatched
Code Analysis
Analyzed Mar 17, 2026

Immocaster WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
74
7 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

9% escaped81 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
immocaster_pages_immobilienscout24_update (pages\immobilienscout24.php:40)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Immocaster WordPress Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionwpcontent_object.php:50
actionadmin_initcontent_resultlist.php:4
actionsave_postcontent_resultlist.php:20
filterthe_contentcontent_resultlist.php:204
filterallowed_redirect_hostsimmocaster.php:29
actioninitimmocaster.php:40
actioninitimmocaster.php:69
filterrewrite_rules_arrayimmocaster.php:72
filterquery_varsimmocaster.php:73
filterwp_loadedimmocaster.php:74
actioninitimmocaster.php:132
actionadmin_headimmocaster.php:142
actionwp_enqueue_scriptsimmocaster.php:155
actionadmin_menuimmocaster.php:174
actionadmin_noticesmessages.php:3
actioninitpages\immobilienscout24.php:33
actioninitpages\immobilienscout24.php:73
actionwidgets_initwidget_teaser.php:3
Maintenance & Trust

Immocaster WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.0
Last updatedSep 30, 2015
PHP min version
Downloads6K

Community Trust

Rating46/100
Number of ratings3
Active installs10
Developer Profile

Immocaster WordPress Plugin Developer Profile

Hinnerk Altenburg

1 plugin · 10 total installs

67
trust score
Avg Security Score
61/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Immocaster WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/immocaster/lib/galleria/galleria-1.2.6.wp-version.min.js/wp-content/plugins/immocaster/js/ajax.js/wp-content/plugins/immocaster/lib/jquery-ui/css/smoothness/jquery-ui-1.10.0.custom.min.css/wp-content/plugins/immocaster/css/admin.css/wp-content/plugins/immocaster/custom/css/style.css/wp-content/plugins/immocaster/default/css/style.css
Script Paths
lib/galleria/galleria-1.2.6.wp-version.min.jsjs/ajax.js
Version Parameters
immocaster/lib/galleria/galleria-1.2.6.wp-version.min.js?ver=immocaster/js/ajax.js?ver=immocaster/lib/jquery-ui/css/smoothness/jquery-ui-1.10.0.custom.min.css?ver=immocaster/css/admin.css?ver=immocaster/custom/css/style.css?ver=immocaster/default/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
immocaster_mb_resultlist_region
Data Attributes
immocaster_mb_resultlist_all_regions
JS Globals
immocaster_ajax
FAQ

Frequently Asked Questions about Immocaster WordPress Plugin