Impact
The Real Estate Manager plugin for WordPress permits an authenticated user with subscriber or higher privileges to supply arbitrary content to the before_price_text parameter via a vulnerable Ajax handler. The handler and its storage process lack capability checks, nonce verification, and output escaping; the value is persisted as post meta without wp_kses filtering, enabling malicious JavaScript injection. When a page displays this meta value, the script executes in any visitor’s browser, giving attackers client‑side code execution that can steal data, hijack sessions, or deface the site. The flaw corresponds to CWE‑79.
Affected Systems
All installations of the Real Estate Manager – Property Listing and Agent Management plugin authored by Rameez Iqbal running version 7.3 or earlier are affected. No later versions have been reported vulnerable. The plugin is distributed via the WordPress plugin repository and is deployed on WordPress sites that rely on its real‑estate listing functionality.
Risk and Exploitability
With a CVSS base score of 6.4 the vulnerability is considered moderate to high severity. The EPSS score is not available and it is not listed in CISA’s KEV catalog, indicating no widely known exploitation yet. Nevertheless, exploitation requires only authenticated access, and the Ajax endpoint’s lack of capability or nonce checks makes it easy for any user with subscriber‑level or higher privileges – or a compromised account – to inject malicious scripts. Because the injected script runs in the context of any visitor to the site, the risk extends to end users, making the issue high‑priority for remediation.
OpenCVE Enrichment