Impact
The vulnerability is a Reflected Cross‑Site Scripting flaw that allows an attacker to inject and execute malicious JavaScript in a victim’s browser when they visit a crafted URL or submit a vulnerable form. The injected script can capture session cookies, hijack user sessions, deface pages, or redirect users to phishing sites. The weakness is a Classic Input Validation problem, identified as CWE‑79.
Affected Systems
WebCodingPlace Real Estate Manager Pro plugin for WordPress, versions up to and including 12.8.3. Any deployment of this plugin in a WordPress site is impacted.
Risk and Exploitability
The CVSS score of 7.1 reflects a moderate‑high impact for a low barrier to exploitation. The EPSS score of less than 1% indicates a low probability of active exploitation at this time, and the vulnerability is not listed in CISA KEV. The likely attack vector is a crafted HTTP request to an endpoint that reflects unsanitised input back into the page, and no authentication is required. The risk is therefore moderate, but remediation is strongly advised.
OpenCVE Enrichment