Impact
The ListingPro plugin for WordPress does not properly sanitize user input when generating web pages, which allows an attacker to inject malicious JavaScript into responses. The injected script executes in the context of the victim's browser, potentially leading to credential theft, session hijacking, or defacement. This vulnerability falls under the Common Weakness Enumeration category CWE‑79.
Affected Systems
CridioStudio ListingPro plugin for WordPress, affecting all releases from the initial versions up to and including 2.9.8. Sites running this plugin on a WordPress installation may be exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑medium severity, while the EPSS score of less than 1% suggests that the probability of exploitation is currently low. The vulnerability is not listed in CISA’s KEV catalog, meaning no confirmed exploit has been widely reported. Likely attack vectors involve crafted URLs or form inputs that are reflected back to the user without sanitization, enabling attackers to deliver payloads to unsuspecting visitors.
OpenCVE Enrichment