Impact
The Houzez Property Feed plugin for WordPress has a Cross‑Site Request Forgery vulnerability that allows an attacker to delete property feed exports. The flaw is caused by missing or incorrect nonce validation on the deleteexport action. When exploited, an attacker can cause the loss of exported data, impacting the integrity and availability of the property listings provided by the feed.
Affected Systems
WordPress sites using the propertyhive Houzez Property Feed plugin version 2.4.21 or earlier are affected. Site administrators who have the ability to trigger the deleteexport action are the direct concern, as the vulnerability requires an authenticated administrator to execute the forged request.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low probability of being actively exploited. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to trick an administrator into visiting a crafted URL or clicking a malicious link, making the attack vector a human‑mediated Cross‑Site Request Forgery.
OpenCVE Enrichment
EUVD