vendor:
Real Estate 7 - Real Estate WordPress Theme
by:
m0ze
N/A
CVSS
N/A
Persistent XSS Injection
79
CWE
Product Name: Real Estate 7 - Real Estate WordPress Theme
Affected Version From: <= 2.8.9
Affected Version To: <= 2.8.9
Patch Exists: NO
Related CWE: -
CPE: -
Platforms Tested: NginX
2019
Real Estate 7 – Real Estate WordPress Theme v2.8.9 Persistent XSS Injection
The Real Estate 7 premium WordPress theme is vulnerable to persistent XSS injection that allows an attacker to inject JavaScript or HTML code into the website front-end. The attacker can steal admin or moderator cookies and edit existing listings on the website by changing the unique ID.
Mitigation:
Unknown