Description
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
Published: 2026-07-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Real Estate Manager Pro plugin contains an unauthenticated reflected cross‑site scripting flaw in all releases up to and including version 12.8.5. This weakness allows an attacker to insert arbitrary JavaScript into HTTP responses that are rendered by users of the affected site. When rendered, the injected script executes with the privileges of the site, potentially compromising page content or enabling further attacks. This type of vulnerability is classified as CWE‑79.

Affected Systems

WordPress sites that use the Real Estate Manager Pro plugin from WebCodingPlace with a version of 12.8.5 or earlier.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity level. The EPSS score of less than 1% suggests that, at present, the likelihood of exploitation is low, though the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered without authentication—typically by accessing a crafted URL or manipulated header—an attacker only needs to convince a visitor to follow a malicious link or load a page containing the vulnerable response to succeed.

Generated by OpenCVE AI on August 3, 2026 at 22:27 UTC.

Remediation

Vendor Solution

Update the WordPress Real Estate Manager Pro Plugin to the latest available version (at least 12.8.6).


OpenCVE Recommended Actions

  • Update the WordPress Real Estate Manager Pro plugin to version 12.8.6 or later.
  • If an immediate update is not possible, disable the plugin on the production environment until a patch can be applied.
  • Apply a content‑security‑policy header or use a web application firewall to block or filter injected script content while the permanent fix is awaited.

Generated by OpenCVE AI on August 3, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Webcodingplace
Webcodingplace real Estate Manager
Wordpress
Wordpress wordpress
Vendors & Products Webcodingplace
Webcodingplace real Estate Manager
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
Title WordPress Real Estate Manager Pro plugin <= 12.8.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Webcodingplace Real Estate Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:40:27.605Z

Reserved: 2026-06-25T08:03:56.313Z

Link: CVE-2026-57701

cve-icon Vulnrichment

Updated: 2026-07-23T13:40:20.295Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:29.440

Modified: 2026-07-23T14:17:25.213

Link: CVE-2026-57701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')