Impact
The SimplyRETS Real Estate IDX plugin for WordPress contains an improper neutralization of user input during webpage generation that leads to reflected Cross‑Site Scripting (XSS). An attacker can embed malicious JavaScript into a crafted URL, and when a victim opens the URL, the script executes in the victim’s browser under the site’s domain.
Affected Systems
The vulnerability affects all installations of the ReichertBrothers SimplyRETS Real Estate IDX plugin for WordPress from the earliest released version up to and including version 3.2.2.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential impact. The EPSS score of less than 1% suggests that exploitation is currently rare. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires a user to visit a specially crafted URL containing malicious JavaScript, making it a user‑interaction attack vector.
OpenCVE Enrichment
EUVD