Sceawere
Vulnerability Detail
CVE-2026-96667UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Real Estate Manager
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 2h ago
- Vendor
- rameez_iqbal
- Product
- Real Estate Manager – Property Listing and Agent Management
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The reCAPTCHA check is trivially bypassed by omitting the g-recaptcha-response parameter entirely, since validation only runs when that parameter is present.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T06:16:45.230Z",
"pubdate": "2026-10-10T06:16:45.230Z",
"executiveSummary": "The Real Estate Manager – Property Listing and Agent Management plugin for WordPress contains a critical Stored Cross-Site Scripting (XSS) vulnerability affecting versions 7.3 and earlier.\nThe vulnerability originates from inadequate input sanitization and output escaping on the 'first_name' parameter, allowing unauthenticated attackers to inject malicious JavaScript payloads into the application.\nFurthermore, the reCAPTCHA validation mechanism is insecurely implemented, as the verification logic is conditionally skipped if the 'g-recaptcha-response' parameter is entirely omitted from the request.\nThis combination allows remote, unauthenticated actors to execute arbitrary code within the context of other users' sessions, including administrative sessions.\nSuccessful exploitation poses a severe risk, as it enables session hijacking, unauthorized actions, site defacement, and potential credential theft.\nThe vulnerability is accessible over the network without requiring prior authentication, significantly increasing the attack surface.",
"technicalDetails": "The root cause of this vulnerability is improper handling of user-supplied data within the 'first_name' parameter, which is processed by the plugin without sufficient server-side sanitization or contextual output escaping.\nThe application stores the malicious script directly into the database. When an administrative or authenticated user views the compromised records, the stored payload is rendered by the victim's browser, leading to the execution of the injected script.\nA secondary, critical flaw exists within the plugin's security control logic: the reCAPTCHA validation mechanism. The implementation only triggers validation routines if the 'g-recaptcha-response' parameter is present in the HTTP POST request. An attacker can trivially bypass this control by omitting the parameter entirely, which causes the plugin to bypass the security check and accept the malicious input as valid.\nThe attack flow proceeds as follows: First, the attacker crafts a malicious payload containing JavaScript, such as a session cookie exfiltration script. Second, the attacker sends an HTTP POST request to the plugin's submission endpoint, intentionally excluding the 'g-recaptcha-response' parameter to bypass reCAPTCHA validation. Third, the plugin, failing to sanitize the 'first_name' input, writes the payload directly to the database.\nWhen an authorized administrator accesses the management dashboard or a page displaying the affected property/agent details, the application retrieves the stored script and injects it into the HTML document. The victim’s browser executes the script automatically due to the lack of context-aware output encoding.\nThis vulnerability is particularly severe because the payload executes in the context of the victim's session, granting the attacker the same permissions as the victim. If an administrator views the listing, the attacker could theoretically perform administrative actions, modify settings, or inject additional persistent backdoors. The vulnerability exists in all plugin versions up to and including 7.3, and there is currently no requirement for valid credentials to trigger the injection, making it a high-risk entry point for remote exploitation."
}