Impact
The vulnerability allows attackers to inject arbitrary client‑side scripts without authentication in the Qode Real Estate WordPress plugin. By exploiting unsanitized user input, a malicious actor can execute code in the context of any site visitor, potentially stealing session tokens, defacing pages, or redirecting users to phishing sites. The flaw directly compromises confidentiality, integrity and availability of the affected website from the perspective of end users.
Affected Systems
WordPress sites running the Qode Real Estate plugin version 1.1.7.3 or earlier, provided by the vendor Qode. The vulnerability is limited to this specific plugin and does not affect other WordPress components.
Risk and Exploitability
According to the CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation at this time. Attackers can trigger the flaw by presenting a crafted URL or form that stores malicious payloads in the plugin’s data fields. Because no authentication is needed, any visitor to the affected site may be exploited. Given the lack of exploitation data, the risk remains theoretical, but best practice recommends patching immediately.
OpenCVE Enrichment