Impact
The vulnerability arises because the Realtyna Organic IDX and WPL Real Estate plugins mirror data from the location selector endpoint directly into the web page without sanitising or escaping it, constituting a reflected XSS (CWE‑79) flaw. An unauthenticated attacker can build a specially crafted URL that embeds malicious JavaScript, and if a site visitor clicks that URL the script runs in their browser. Because the flaw does not grant server‑side code execution or privilege escalation, the impact is confined to the victim’s session; however, it can be used to steal cookies, hijack the user’s session, perform phishing, or otherwise manipulate the client side.
Affected Systems
All installations of the Realtyna Organic IDX or WPL Real Estate WordPress plugins running a version earlier than 5.4.2 are affected. The flaw exists in the location selector endpoint present in any pre‑5.4.2 release of the plugin stack.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity vulnerability, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. Attackers must construct a malicious URL and lure a visitor to click it—a typical reflected XSS attack that relies on social engineering. Successful exploitation can lead to compromise of user sessions, theft of credentials, or delivery of phishing content. While the server itself remains uncompromised, the risk to a site hosting a large or valuable user base is that a single crafted link could affect many visitors.
OpenCVE Enrichment