Skip to content
Threat Feed
high advisory

Stored XSS in Real Estate Manager WordPress Plugin via CVE-2026-96667

The Real Estate Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization of the first_name parameter, allowing unauthenticated attackers to bypass reCAPTCHA and execute arbitrary scripts.

CVE search metadata

CVE search record: CVE-2026-96667. Severity: high. CVSS: 7.2. KEV: no. Product: Real Estate Manager – Property Listing and Agent Management (<= 7.3). Brief: Stored XSS in Real Estate Manager WordPress Plugin via CVE-2026-96667. Brief link: https://feed.craftedsignal.io/briefs/2026-10-real-estate-manager-xss/

The Real Estate Manager - Property Listing and Agent Management plugin for WordPress, in versions up to and including 7.3, contains a critical security flaw identified as CVE-2026-96667. The vulnerability manifests as a Stored Cross-Site Scripting (XSS) condition caused by improper input sanitization and output escaping within the 'first_name' parameter. Furthermore, the plugin's reCAPTCHA implementation is flawed, as it only validates the request if the 'g-recaptcha-response' parameter is present; an attacker can completely bypass this check by simply omitting the parameter from their HTTP request. This vulnerability allows an unauthenticated attacker to inject arbitrary malicious scripts, which will execute within the browser context of any user who views the affected page, leading to potential session hijacking or unauthorized administrative actions.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. This may result in session theft, unauthorized account modifications, or redirection of users to malicious sites. The scope of impact is limited to sites running the vulnerable Real Estate Manager plugin version 7.3 or lower, which is widely utilized in the real estate sector.

Recommendation

  • Update the Real Estate Manager - Property Listing and Agent Management plugin to a version released after 7.3 immediately.
  • Monitor server logs for HTTP POST requests to the plugin's submission endpoints containing script tags or JavaScript event handlers in the 'first_name' field.
  • Implement a Web Application Firewall (WAF) rule to inspect input fields for common XSS payloads, specifically targeting the 'first_name' parameter.

Immediate actions

Update Real Estate Manager plugin to version > 7.3

IT Operations 24h

Mitigations

Patch plugin or disable functionality until update is applied

immediate IT Operations

CVE-2026-96667