Junglewise Threat Intelligence

CVE-2026-57701: WebCodingPlace Real Estate Manager Pro unauthenticated XSS

CVE-2026-57701 · Severity: high · CVSS 7.1 · Published 2026-07-23

Executive brief

Real Estate Manager Pro, a WordPress plugin used for managing property listings, contains a security vulnerability that allows attackers to inject malicious scripts into the website. An attacker can exploit this by tricking a site visitor or administrator into clicking a specially crafted link. If successful, this could lead to unauthorized actions being performed in the user's browser, such as redirecting visitors to malicious sites or stealing session information.

Technical details

The Real Estate Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a crafted URL to a user. When the victim visits the link, the malicious script is executed within the context of their browser session. This can lead to session hijacking, unauthorized administrative actions, or website defacement. The vulnerability is patched in version 12.8.6.

Affected products

  • WebCodingPlace Real Estate Manager Pro <= 12.8.5

Timeline

  • 2026-06-07: other: Reported by researcher dutafi
  • 2026-07-20: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD
  • 2026-07-23: patched: Version 12.8.6 released to address the issue

References

Related threats