Junglewise Threat Intelligence

CVE-2026-16684: mervb1 Easy Property Listings Stored XSS in facebook contact method

CVE-2026-16684 · Severity: medium · CVSS 6.4 · Published 2026-08-01

Executive brief

The Easy Property Listings plugin for WordPress, which is used to manage real estate listings, contains a security flaw in how it handles user profile information. An attacker with a basic user account can inject malicious scripts into the 'facebook' contact field. These scripts will then run automatically in the browser of any visitor or administrator who views the affected profile or listing page, potentially leading to unauthorized actions or data theft.

Technical details

The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'facebook' User Contact Method field. This vulnerability allows authenticated attackers with subscriber-level permissions or higher to inject arbitrary web scripts into the database. These scripts are subsequently executed in the context of a user's browser whenever they navigate to a page displaying the compromised contact information. The issue is present in all versions up to and including 3.5.24; users should update to a patched version if available.

Affected products

  • mervb1 Easy Property Listings <= 3.5.24

Timeline

  • 2026-08-01: disclosed
  • 2026-08-01: advisory

References