Junglewise Threat Intelligence

CVE-2026-57343: Contempoinc Real Estate 7 XSS in WordPress theme

CVE-2026-57343 · Severity: high · CVSS 7.1 · Published 2026-07-02

Technologies: Contempoinc Real Estate 7.

Executive brief

The Real Estate 7 theme for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs because the theme does not properly sanitize user-provided data, potentially leading to unauthorized redirects, the display of fraudulent advertisements, or the theft of user session information. An exploit typically requires a site visitor or administrator to click a specially crafted link.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Real Estate 7 theme for WordPress (versions 3.5.9 and below) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject malicious scripts via a crafted network request. Successful exploitation requires user interaction, such as a victim clicking a malicious link, which then executes the script within the context of the victim's browser session. This can lead to session hijacking or unauthorized actions performed on behalf of the user. The issue is resolved in version 3.6.0.

Affected products

  • Contempoinc Real Estate 7 <= 3.5.9

Timeline

  • 2026-04-29: disclosed: Reported by João Pedro S Alcântara (Kinorth)
  • 2026-06-29: advisory: Patchstack published advisory
  • 2026-07-02: advisory: NVD published CVE-2026-57343
  • 2026-06-29: patched: Version 3.6.0 released to address the vulnerability

References