Official Product Homepageproduct
https://fruitfulcode.com/ CVE-2019-25742
MEDIUM
WordPress Theme Zoner Real Estate 4.1.1 Persistent XSS
Record summary
CVE-2019-25742 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when creating properties. Attackers can inject JavaScript payloads in the property creation form that execute when administrators view the property for approval, enabling cookie theft and session hijacking.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Zoner Real EstateBrowse Fruitfulcode / Zoner Real Estate | CVE List | 4.1.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Theme Zoner Real Estate - 4.1.1 Persistent Cross-Site ScriptingExploitDB exploitby m0zeNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25742 Product Referenceproduct
https://themeforest.net/item/zoner-real-estate-wordpress-theme/9099226 ExploitDB-47436exploit
https://www.exploit-db.com/exploits/47436 VulnCheck Advisory: WordPress Theme Zoner Real Estate 4.1.1 Persistent XSSThird-party advisory
https://www.vulncheck.com/advisories/wordpress-theme-zoner-real-estate-persistent-xss