Record summary

CVE-2022-3933 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Essential Real Estate

Default status: unaffected

CVE ListBefore 3.9.6affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Essential Real Estate <3.9.6 - Authenticated Cross-Site ScriptingCVSS 5.4

WordPress Essential Real Estate plugin before 3.9.6 contains an authenticated cross-site scripting vulnerability. The plugin does not sanitize and escape some parameters, which can allow someone with a role as low as admin to inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow theft of cookie-based authentication credentials and launch of other attacks.

Impact

An authenticated attacker can inject malicious scripts into the website, potentially leading to unauthorized access, data theft, or further attacks.

Remediation

Fixed in version 3.9.6.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2022wpscanauthenticatedwordpresswp-pluginwpessential-real-estatexssg5themevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:g5theme:essential_real_estate:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2