Impact
Improper neutralization of input during web page generation allows an attacker to inject malicious scripts into a page rendered by the CridioStudio ListingPro WordPress plugin. The primary impact is that a victim who views the affected page can have arbitrary JavaScript executed in their browser, which may affect the confidentiality or integrity of the victim’s session on that site. The weakness is classified as CWE‑79.
Affected Systems
Any WordPress installation using the ListingPro plugin up to and including version 2.9.9 is affected. The vulnerability is triggered whenever the plugin renders content without properly escaping user-supplied input, regardless of the site’s administrative privilege level.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% indicates a very low probability of public exploitation at present. The flaw is not listed in the CISA KEV catalog. The likely attack vector is via a page that incorporates unescaped plugin output; an attacker may lure a user to such a page through social engineering or by inserting malicious data into a field processed by the plugin.
OpenCVE Enrichment