Impact
The HivePress plugin is vulnerable to stored cross‑site scripting when an administrator configures a custom text attribute so that its display format places the %value% token inside an HTML attribute, such as title="%value%". Authenticated users at the subscriber level or higher can submit any value for that field. Because the plugin does not sanitise or escape the input, the value is stored and later rendered into an HTML attribute, allowing an attacker to inject arbitrary JavaScript that executes in the browsers of any user viewing the affected listing page. The flaw corresponds to CWE‑79 and can lead to code execution, session hijacking, defacement, and data theft.
Affected Systems
HivePress – Business Directory, Listings & Classified Ads Plugin for WordPress, all releases up to and including version 1.7.31. The issue is fixed in release 1.7.32 and later.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, so active exploitation data is unknown. However, the attack requires only subscriber‑level access and the presence of a vulnerable attribute configuration, both common in WordPress environments. An attacker can easily create a subscriber account, supply a malicious payload in a custom attribute, and then cause the payload to execute whenever another user visits the associated listing. The combination of moderate severity and realistic exploitation conditions means this vulnerability should be treated as high priority and addressed promptly.
OpenCVE Enrichment