Impact
The Real Estate Pro WordPress plugin allows an authenticated attacker with administrator privileges to inject arbitrary JavaScript into stored settings. When another user visits the affected page, the injected script executes in their browser, potentially compromising their session or defacing the site. This is a classic Stored XSS flaw (CWE‑79).
Affected Systems
The vulnerability affects installations of Real Estate Pro version 1.0.9 or earlier, specifically when WordPress is configured as a multi‑site network and the unfiltered_html capability is disabled. The plugin is distributed by the vendor bhubbard.
Risk and Exploitability
With a CVSS score of 5.5 the flaw is moderate but still significant, especially given that it requires only an authenticated admin account. No public exploit is documented and the EPSS score is not available, but the risk remains due to the potential for malicious script injection. The vulnerability is not listed in the CISA KEV catalog, yet its impact on user data and trustworthiness makes patching advisable.
OpenCVE Enrichment