Junglewise Threat Intelligence

CVE-2026-57381: Property Hive PropertyHive Reflected XSS

CVE-2026-57381 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

PropertyHive is a WordPress plugin used by real estate agencies to manage and display property listings. A security vulnerability in this plugin allows attackers to inject malicious scripts into the website, which are then executed in the browsers of other users. This could lead to unauthorized actions being performed on behalf of site administrators, theft of session cookies, or the redirection of visitors to malicious websites.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Property Hive PropertyHive plugin for WordPress (versions up to and including 2.2.3). The flaw stems from the improper neutralization of input during web page generation, allowing an unauthenticated remote attacker to inject arbitrary web scripts. Exploitation requires a victim (typically a site administrator or user) to interact with a specially crafted link or form. Successful exploitation can lead to the execution of malicious JavaScript in the context of the victim's session, potentially resulting in session hijacking or unauthorized site modifications. The issue is addressed in version 2.2.4.

Affected products

  • Property Hive PropertyHive <= 2.2.3

Timeline

  • 2026-06-04: other: Reported by researcher manop55555
  • 2026-07-07: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD
  • 2026-07-13: patched: Patch confirmed available in version 2.2.4

References

Related threats