Impact
Unauthenticated Cross Site Scripting can be triggered by supplying crafted input to the SimplyRETS Real Estate IDX plugin. The CVE explicitly notes that user-supplied data is reflected without adequate sanitization, permitting execution of arbitrary JavaScript within the browser context of site visitors. The flaw does not require authentication.
Affected Systems
WordPress sites using the ReichertBrothers SimplyRETS Real Estate IDX plugin version 3.2.8 or earlier are affected. Any site running these versions should be examined for the presence of the plugin.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity. EPSS score of 0.00146, and the vulnerability is not listed in the CISA KEV catalog, implying limited visibility of active exploitation. However, because authentication is not required, an attacker can inject scripts through public interfaces, potentially allowing malicious code to be executed in the browsers of visitors who access the affected site.
OpenCVE Enrichment