Junglewise Threat Intelligence

CVE-2026-57398: WebCodingPlace Real Estate Manager Pro Reflected XSS

CVE-2026-57398 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

WebCodingPlace Real Estate Manager Pro, a WordPress plugin used for managing property listings, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks on a specially crafted link, the attacker could execute code in their browser, potentially leading to unauthorized actions, data theft, or website defacement. This vulnerability is particularly dangerous as it can be used in automated attacks against many websites simultaneously.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the WebCodingPlace Real Estate Manager Pro plugin for WordPress (versions up to and including 12.8.3). The flaw stems from the application's failure to properly sanitize or neutralize user-supplied input before including it in generated web pages. An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 12.8.4.

Affected products

  • WebCodingPlace Real Estate Manager Pro <= 12.8.3

Timeline

  • 2026-04-24: disclosed: Reported by dutafi
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published CVE record
  • 2026-07-08: patched: Version 12.8.4 released

References

Related threats