Impact
The vulnerability is a reflected XSS flaw in SmartDataSoft’s Essential WP Real Estate plugin. It permits attackers to inject arbitrary HTML or JavaScript that is returned to the user’s browser. When a victim visits a specially crafted URL or submits a malicious form, the plugin fails to escape input, enabling client‑side code execution. Successful exploitation can lead to cookie theft, session hijacking, defacement, or downstream attacks. The weakness corresponds to CWE‑79, an improper neutralization of input.
Affected Systems
This flaw affects all installations of SmartDataSoft’s Essential WP Real Estate plugin version 1.1.3 or earlier on WordPress sites. Any WordPress environment that hosts the plugin is potentially vulnerable, regardless of the underlying operating system or server configuration.
Risk and Exploitability
The CVSS score is 7.1, marking high severity, while the EPSS score is below 1 %, indicating a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; an attacker only needs to craft a URL or form containing malicious payloads. Because the flaw is reflected and executes on the client side, the conditions for exploitation are minimal: a user must load the crafted page in their browser, and no additional privileges are required by the attacker.
OpenCVE Enrichment
EUVD