Impact
The vulnerability is a reflected Cross Site Scripting flaw due to improper neutralization of user input in the PropertyHive plugin, allowing an attacker to inject arbitrary JavaScript that is executed in the browser of any user who views a page reflecting the input. No additional exploitation conditions are specified.
Affected Systems
WordPress installations that use the PropertyHive plugin version 2.2.3 or earlier.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is less than 1%, suggesting exploitation is currently rare. The vulnerability is not listed in CISA KEV. The likely attack vector is web‑based, requiring an attacker to craft a URL or form submission that the plugin reflects; no elevated privileges are required by the description.
OpenCVE Enrichment