Impact
Persistent cross‑site scripting exists in the Address field of the property creation form. An authenticated agent can enter a JavaScript payload that is stored on the server and executed when an administrator views the property for approval, permitting cookie theft and session hijacking.
Affected Systems
The vulnerability affects the WordPress theme Zoner Real Estate version 4.1.1, published by Fruitfulcode. Only this version is known to be impacted; newer releases should be evaluated.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity vulnerability. No EPSS score is available, and it is not listed in the CISA KEV catalog. The required conditions are that the attacker has a valid WordPress agent account. After inserting malicious content during property creation, the attacker must wait until an administrator reviews and approves the property, at which point the script runs and can steal session data. Because the attack vector requires authenticated use and depends on an untrusted administrator reviewing the content, exploitation is plausible in environments where agent and admin roles overlap or administrators routinely approve properties.
OpenCVE Enrichment