Junglewise Threat Intelligence

CVE-2026-42729: Property Hive PropertyHive DOM-based XSS

CVE-2026-42729 · Severity: high · CVSS 7.1 · Published 2026-05-27

Executive brief

PropertyHive, a popular WordPress plugin used for managing real estate listings, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site visitor or administrator clicks on a specially crafted link, the attacker could potentially steal session information, redirect users to fraudulent websites, or perform actions on behalf of the user. This could lead to unauthorized access to the website's management interface or damage the site's reputation.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Property Hive PropertyHive plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw allows unauthenticated attackers to inject malicious scripts into the Document Object Model (DOM) environment. Exploitation requires a victim to interact with a malicious link or crafted page (User Interaction). Once executed, the script runs in the context of the victim's browser session, potentially allowing for session hijacking, cookie theft, or unauthorized administrative actions if the victim is a site manager. The issue is fixed in version 2.2.3.

Affected products

  • Property Hive PropertyHive <= 2.2.2

Timeline

  • 2026-04-23: other: Reported by researcher HaiND
  • 2026-05-23: advisory: Initial advisory published by Patchstack
  • 2026-05-27: disclosed: CVE published to NVD

References