Impact
The vulnerability is a Cross‑Site Scripting flaw that permits contributors to inject arbitrary HTML into PropertyHive plugin pages. An attacker can submit malicious scripts that are rendered in the browser of other site visitors, leading to session hijacking or defacement. This flaw is categorized as CWE-79, reflecting improper handling of user input.
Affected Systems
The affected software includes the WordPress PropertyHive plugin, version 2.2.6 and earlier. The product is maintained by Property Hive. The official fix is to upgrade to version 2.3.0 or later.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate level of risk. No EPSS data is available and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote, exploiting user‑provided content through the plugin’s entry forms. An attacker with access to the contributor interface could deliver the malicious payload, and any visitor to the affected site would then execute it in their browser.
OpenCVE Enrichment