Impact
The Real Estate Manager Pro plugin contains an unauthenticated reflected cross‑site scripting flaw in all releases up to and including version 12.8.5. This weakness allows an attacker to insert arbitrary JavaScript into HTTP responses that are rendered by users of the affected site. When rendered, the injected script executes with the privileges of the site, potentially compromising page content or enabling further attacks. This type of vulnerability is classified as CWE‑79.
Affected Systems
WordPress sites that use the Real Estate Manager Pro plugin from WebCodingPlace with a version of 12.8.5 or earlier.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity level. The EPSS score of less than 1% suggests that, at present, the likelihood of exploitation is low, though the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered without authentication—typically by accessing a crafted URL or manipulated header—an attacker only needs to convince a visitor to follow a malicious link or load a page containing the vulnerable response to succeed.
OpenCVE Enrichment