CVE-2019-25742
MEDIUMWordPress Theme Zoner Real Estate 4.1.1 Persistent XSS
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25742. PoCs published by m0ze.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in WordPress Theme Zoner Real Estate 4.1.1, where an attacker can inject malicious JavaScript via the 'Address' field when creating a property. It also includes an IDOR vulnerability allowing unauthorized deletion of any post or page.
Description
WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when creating properties. Attackers can inject JavaScript payloads in the property creation form that execute when administrators view the property for approval, enabling cookie theft and session hijacking.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in WordPress Theme Zoner Real Estate 4.1.1, where an attacker can inject malicious JavaScript via the 'Address' field when creating a property. It also includes an IDOR vulnerability allowing unauthorized deletion of any post or page.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N