A vulnerability, which was classified as critical, was found in WebCodingPlace Real Estate Manager Pro Plugin up to 12.8.6 on WordPress. This affects the function
allow_attachment_actions. The manipulation results in improper privilege management.
This vulnerability is known as CVE-2026-15142. It is possible to launch the attack remotely. No exploit is available.