CVE-2022-3933
Essential Real Estate < 3.9.6 - Reflected Cross-Site-Scripting
Record summary
CVE-2022-3933 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Essential Real EstateDefault status: unaffected | CVE List | Before 3.9.6 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Essential Real Estate <3.9.6 - Authenticated Cross-Site ScriptingCVSS 5.4
WordPress Essential Real Estate plugin before 3.9.6 contains an authenticated cross-site scripting vulnerability. The plugin does not sanitize and escape some parameters, which can allow someone with a role as low as admin to inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow theft of cookie-based authentication credentials and launch of other attacks.
Impact
An authenticated attacker can inject malicious scripts into the website, potentially leading to unauthorized access, data theft, or further attacks.
Remediation
Fixed in version 3.9.6.
Source: ProjectDiscovery