Impact
Improper neutralization of user input during page generation in the Real Estate Pro plugin allows an attacker to embed malicious scripts that are reflected in the victim’s browser. This reflected XSS flaw is identified as CWE‑79 and can enable e‑mail login hijacking, phishing, or the execution of arbitrary JavaScript in the context of the user’s session.
Affected Systems
The vulnerability affects the e‑plugins Real Estate Pro WordPress plugin versions through 2.1.4. Any installation of the plugin at or below this version is susceptible to the reflected XSS issue.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact potential, while the EPSS score of less than 1% suggests that exploitation probability is currently low. The vulnerability is not listed in the CISA KEV catalog. Based on the description the likely attack vector is a crafted URL or query string that a victim is tricked into visiting, which would cause the reflected script to run in the victim’s browser.
OpenCVE Enrichment