Impact
Unauthenticated Cross Site Scripting in the Houzez Property Feed plugin allows a malicious actor to embed arbitrary client‑side scripts into web pages served by the affected WordPress site. If an attacker successfully injects JavaScript, they may hijack user sessions, deface content, or redirect users to phishing sites. The weakness is a classic input‑validation flaw (CWE‑79) that permits reflected script execution without any credentials.
Affected Systems
The issue affects the Property Hive Houzez Property Feed plugin for WordPress, specifically all releases up to and including version 2.5.48. Sites that have not applied the 2.5.49 update remain vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies this vulnerability as High. Because the attack is unauthenticated and can be triggered by any user accessing the vulnerable endpoint, the likelihood of exploitation is significant even though EPSS data is not published and the flaw is not listed in the CISA KEV catalog. Attackers would need only a crafted URL or input that reaches the vulnerable plugin endpoint; no special privileges are required.
OpenCVE Enrichment