Executive brief
PropertyHive is a popular WordPress real estate management plugin used to list and manage property listings. A stored cross site scripting vulnerability allows contributors with plugin-level access to inject malicious scripts that can steal visitor data, hijack accounts, or perform unauthorized actions on the site in the name of visitors.
Technical details
PropertyHive versions 2.2.6 and earlier are vulnerable to stored cross site scripting (XSS) due to insufficient input validation or output encoding in contributor-accessible functionality. The vulnerability requires a user with at least Contributor role privileges to inject malicious JavaScript payloads into the plugin's data. Once injected, the scripts execute in the browsers of site visitors and other administrators who view the affected content, allowing theft of session cookies, account hijacking, or data exfiltration. The vulnerability was patched in version 2.3.0.
Affected products
- PropertyHive PropertyHive ≤ 2.2.6
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: version 2.3.0