Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected Cross Site Scripting flaw due to improper neutralization of user input in the PropertyHive plugin, allowing an attacker to inject arbitrary JavaScript that is executed in the browser of any user who views a page reflecting the input. No additional exploitation conditions are specified.

Affected Systems

WordPress installations that use the PropertyHive plugin version 2.2.3 or earlier.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. The EPSS score is less than 1%, suggesting exploitation is currently rare. The vulnerability is not listed in CISA KEV. The likely attack vector is web‑based, requiring an attacker to craft a URL or form submission that the plugin reflects; no elevated privileges are required by the description.

Generated by OpenCVE AI on July 31, 2026 at 12:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PropertyHive plugin to version 2.2.4 or later to eliminate the XSS flaw.
  • If an upgrade cannot be performed immediately, implement a strict Content‑Security‑Policy that blocks inline scripts and limits script sources to trusted origins.
  • Review any exposed input fields or endpoints that allow arbitrary user input to be reflected and remove or sanitize them.

Generated by OpenCVE AI on July 31, 2026 at 12:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Propertyhive
Propertyhive propertyhive
Wordpress
Wordpress wordpress
Vendors & Products Propertyhive
Propertyhive propertyhive
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.
Title WordPress PropertyHive plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Propertyhive Propertyhive
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:48:41.243Z

Reserved: 2026-06-24T12:45:54.516Z

Link: CVE-2026-57381

cve-icon Vulnrichment

Updated: 2026-07-13T13:48:37.287Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')