EIP-2026-114347
PRE-CVEWordPress Theme Real Estate 2.8.9 - Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114347. PoCs published by m0ze.
AI-analyzed exploit summary The exploit demonstrates a persistent XSS vulnerability in the Real Estate 7 WordPress theme (v2.8.9 and below) by injecting malicious JavaScript into the 'Virtual Tour Embed' field during listing submission. The payload executes when the listing is viewed, potentially allowing cookie theft or other client-side attacks.
Description
WordPress Theme Real Estate 2.8.9 - Cross-Site Scripting
Exploits (1)
The exploit demonstrates a persistent XSS vulnerability in the Real Estate 7 WordPress theme (v2.8.9 and below) by injecting malicious JavaScript into the 'Virtual Tour Embed' field during listing submission. The payload executes when the listing is viewed, potentially allowing cookie theft or other client-side attacks.