Description
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
Published: 2026-08-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Cross Site Scripting in the Houzez Property Feed plugin allows a malicious actor to embed arbitrary client‑side scripts into web pages served by the affected WordPress site. If an attacker successfully injects JavaScript, they may hijack user sessions, deface content, or redirect users to phishing sites. The weakness is a classic input‑validation flaw (CWE‑79) that permits reflected script execution without any credentials.

Affected Systems

The issue affects the Property Hive Houzez Property Feed plugin for WordPress, specifically all releases up to and including version 2.5.48. Sites that have not applied the 2.5.49 update remain vulnerable.

Risk and Exploitability

The CVSS score of 7.1 classifies this vulnerability as High. Because the attack is unauthenticated and can be triggered by any user accessing the vulnerable endpoint, the likelihood of exploitation is significant even though EPSS data is not published and the flaw is not listed in the CISA KEV catalog. Attackers would need only a crafted URL or input that reaches the vulnerable plugin endpoint; no special privileges are required.

Generated by OpenCVE AI on August 6, 2026 at 15:46 UTC.

Remediation

Vendor Solution

Update the WordPress Houzez Property Feed Plugin to the latest available version (at least 2.5.49).


OpenCVE Recommended Actions

  • Update the Houzez Property Feed plugin to version 2.5.49 or later immediately.
  • If an update cannot be performed right away, deactivate or delete the plugin to eliminate the attack vector.
  • Apply web‑application firewall rules that block or sanitize any script payloads pointing to the plugin’s endpoints.

Generated by OpenCVE AI on August 6, 2026 at 15:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
Title WordPress Houzez Property Feed plugin <= 2.5.48 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:38.844Z

Reserved: 2026-07-22T08:54:23.962Z

Link: CVE-2026-65560

cve-icon Vulnrichment

Updated: 2026-08-06T16:54:26.982Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')