Impact
The Easy Property Listings plugin for WordPress is vulnerable to stored cross‑site scripting through the 'facebook' user contact method. The flaw arises because input entered via this field is neither properly sanitized nor properly escaped before being stored, allowing an attacker who is authenticated at the subscriber level or higher to inject arbitrary JavaScript. When a user accesses a page that includes the stored data, the injected script executes in that user's browser.
Affected Systems
The vulnerability affects the Easy Property Listings plugin for WordPress, version 3.5.24 and earlier. Any WordPress site that uses this plugin and permits subscriber‑level users to interact with the 'facebook' contact method is impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires authenticated subscriber‑level access to submit a value via the 'facebook' field; once injected, the malicious script runs client‑side in any user's browser that views the affected page.
OpenCVE Enrichment