Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Reflected XSS.This issue affects Flexmls® IDX: from n/a through <= 3.15.9.
Published: 2026-03-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

A reflected cross‑site scripting flaw exists in the Flexmls® IDX WordPress plugin caused by improper neutralization of user input, a weakness identified as CWE‑79. When a victim visits a specially crafted request or submits data that is echoed back in the page, an attacker can inject arbitrary JavaScript. Such injected code can steal credentials, hijack sessions, deface the site, or redirect users to malicious destinations, thereby compromising the confidentiality, integrity, and availability of the WordPress installation.

Affected Systems

The vulnerability affects all releases of the Flexmls® IDX plugin for WordPress up to and including version 3.15.9. Any WordPress site that has installed the plugin at or below this version is at risk; no other components or versions are known to be affected.

Risk and Exploitability

The EPSS score indicates a low exploitation probability (under 1%), and the flaw is not listed in the CISA KEV catalog. Nevertheless, reflected XSS can be triggered simply by a crafted URL or form input, making it readily exploitable by an attacker who can lure a legitimate user to a malicious link. Although a published exploit is not available, the attack surface is accessible via standard web requests, and social engineering can increase the likelihood of victim interaction. The CVSS base score is not disclosed in the report, but the nature of the flaw suggests a high severity assessment under common risk models.

Generated by OpenCVE AI on April 2, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Flexmls® IDX plugin to version 3.16.0 or later.

Generated by OpenCVE AI on April 2, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flexmls Flexmls® IDX allows Reflected XSS.This issue affects Flexmls® IDX: from n/a through 3.15.9. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Reflected XSS.This issue affects Flexmls® IDX: from n/a through <= 3.15.9.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 17 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Flexmls
Flexmls flexmls Idx
Wordpress
Wordpress wordpress
Vendors & Products Flexmls
Flexmls flexmls Idx
Wordpress
Wordpress wordpress

Mon, 16 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flexmls Flexmls® IDX allows Reflected XSS.This issue affects Flexmls® IDX: from n/a through 3.15.9.
Title WordPress Flexmls® IDX plugin <= 3.15.9 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Flexmls Flexmls Idx
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-23T14:14:09.199Z

Reserved: 2026-02-02T12:52:55.300Z

Link: CVE-2026-25369

cve-icon Vulnrichment

Updated: 2026-03-16T15:00:18.095Z

cve-icon NVD

Status : Deferred

Published: 2026-03-16T15:16:21.530

Modified: 2026-04-23T15:37:06.303

Link: CVE-2026-25369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T08:00:10Z

Weaknesses