Impact
The vulnerability is an improper neutralization of input during web page generation, resulting in a DOM‑based cross‑site scripting flaw in the Real Estate Manager plugin. An attacker who can inject malicious script into user input can cause that code to execute in the victim’s browser. This allows the attacker to steal credentials, deface the site, or perform other client‑side attacks, as the flaw is classified under CWE‑79 for output sanitization weaknesses.
Affected Systems
All installations of Rameez Iqbal’s Real Estate Manager plugin for WordPress with a version of 7.3 or earlier are affected. This includes every WordPress site that has not upgraded past the 7.3 release line.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The flaw is not listed in the CISA KEV catalogue, so no public exploits have been documented. The likely attack vector is a user interacting with crafted input or a URL that triggers the DOM‑based XSS, after which arbitrary JavaScript runs in the victim’s context.
OpenCVE Enrichment
EUVD