Sceawere
Vulnerability Detail
CVE-2026-93908UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Real Estate Manager
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 3h ago
- Vendor
- rameez_iqbal
- Product
- Real Estate Manager – Property Listing and Agent Management
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is further enabled by the absence of any capability, nonce, or ownership check on the wp_ajax_rem_create_pro_ajax handler, and because the value is persisted via update_post_meta rather than post_content, the wp_kses filtering tied to the unfiltered_html capability does not apply.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-09-30T09:17:16.630Z",
"pubdate": "2026-09-30T09:17:16.630Z",
"executiveSummary": "The Real Estate Manager – Property Listing and Agent Management plugin for WordPress contains a critical Stored Cross-Site Scripting (XSS) vulnerability in versions up to and including 7.3.\nThis vulnerability originates from improper input sanitization and output escaping within the 'before_price_text' parameter handled by the 'wp_ajax_rem_create_pro_ajax' action.\nThe flaw allows authenticated users with at least subscriber-level permissions to inject malicious JavaScript payloads that execute in the context of a victim's browser when accessing the affected pages.\nBecause the 'wp_ajax_rem_create_pro_ajax' handler lacks necessary security controls, such as nonces, capability checks, or ownership verification, the attack surface is significantly exposed.\nThe data is persisted via 'update_post_meta', which bypasses standard 'wp_kses' filtering that normally enforces the 'unfiltered_html' capability restriction, allowing even non-privileged accounts to bypass security boundaries.\nThe impact includes potential account takeover, session hijacking, or unauthorized administrative actions performed on behalf of the victim.",
"technicalDetails": "The vulnerability resides in the 'wp_ajax_rem_create_pro_ajax' handler, which is responsible for processing property listing submissions. The plugin fails to perform adequate input sanitization on the 'before_price_text' parameter prior to storing it in the WordPress database via the 'update_post_meta' function.\nCrucially, the absence of an authorization check, such as 'current_user_can()', and the failure to implement a nonce check, allows any authenticated user (e.g., a subscriber) to invoke this AJAX handler. This lack of access control constitutes a direct authorization bypass.\nThe persistence mechanism utilized is 'update_post_meta', which stores the input in the 'wp_postmeta' table. Unlike data stored within 'post_content', which is subject to the 'wp_kses' filter and often requires the 'unfiltered_html' capability for raw script entry, post meta values are generally treated as data rather than HTML content. Consequently, the input is saved without being sanitized for executable scripts.\nAn attacker can exploit this by crafting a malicious AJAX request directed at 'admin-ajax.php' with the action 'wp_ajax_rem_create_pro_ajax', supplying a JavaScript payload within the 'before_price_text' field. Upon the execution of the request, the malicious string is stored in the database.\nWhen a legitimate user or administrator navigates to a front-end or back-end view that renders the 'before_price_text' metadata, the injected script is executed within the context of the user's session. Since the input is rendered without sufficient output escaping (such as 'esc_html' or 'esc_js'), the browser interprets the payload as executable code.\nThe exploitation flow is as follows: 1. The attacker authenticates as a subscriber. 2. The attacker triggers the vulnerable 'wp_ajax_rem_create_pro_ajax' AJAX action, injecting a script tag via 'before_price_text'. 3. The server processes the request and persists the meta value without validation. 4. An administrative user visits a page displaying the listing. 5. The malicious script executes in the administrator's session, potentially exfiltrating cookies, modifying content, or creating a new administrative user to achieve persistent compromise of the WordPress installation."
}