EIP-2026-114347

PRE-CVE

WordPress Theme Real Estate 2.8.9 - Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114347. PoCs published by m0ze.

AI-analyzed exploit summary The exploit demonstrates a persistent XSS vulnerability in the Real Estate 7 WordPress theme (v2.8.9 and below) by injecting malicious JavaScript into the 'Virtual Tour Embed' field during listing submission. The payload executes when the listing is viewed, potentially allowing cookie theft or other client-side attacks.

Description

WordPress Theme Real Estate 2.8.9 - Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC
by m0ze · textwebappsphp
https://www.exploit-db.com/exploits/47184

The exploit demonstrates a persistent XSS vulnerability in the Real Estate 7 WordPress theme (v2.8.9 and below) by injecting malicious JavaScript into the 'Virtual Tour Embed' field during listing submission. The payload executes when the listing is viewed, potentially allowing cookie theft or other client-side attacks.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Real Estate 7 WordPress Theme <= 2.8.9
Auth required
Prerequisites: Registered user account · Access to listing submission form
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026