Junglewise Threat Intelligence

CVE-2026-66578: PropertyHive contributor cross site scripting

CVE-2026-66578 · Severity: medium · CVSS 6.5 · Published 2026-09-17

Executive brief

PropertyHive is a popular WordPress real estate management plugin used to list and manage property listings. A stored cross site scripting vulnerability allows contributors with plugin-level access to inject malicious scripts that can steal visitor data, hijack accounts, or perform unauthorized actions on the site in the name of visitors.

Technical details

PropertyHive versions 2.2.6 and earlier are vulnerable to stored cross site scripting (XSS) due to insufficient input validation or output encoding in contributor-accessible functionality. The vulnerability requires a user with at least Contributor role privileges to inject malicious JavaScript payloads into the plugin's data. Once injected, the scripts execute in the browsers of site visitors and other administrators who view the affected content, allowing theft of session cookies, account hijacking, or data exfiltration. The vulnerability was patched in version 2.3.0.

Affected products

  • PropertyHive PropertyHive ≤ 2.2.6

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: version 2.3.0

References

Related threats