<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wordpress:real_estate_manager_property_listing_and_agent_management:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awordpressreal_estate_manager_property_listing_and_agent_management/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:51:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awordpressreal_estate_manager_property_listing_and_agent_management/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Real Estate Manager WordPress Plugin via CVE-2026-96667</title><link>https://feed.craftedsignal.io/briefs/2026-10-real-estate-manager-xss/</link><pubDate>Sat, 10 Oct 2026 07:51:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-real-estate-manager-xss/</guid><description>The Real Estate Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization of the first_name parameter, allowing unauthenticated attackers to bypass reCAPTCHA and execute arbitrary scripts.</description><content:encoded><![CDATA[<p>The Real Estate Manager - Property Listing and Agent Management plugin for WordPress, in versions up to and including 7.3, contains a critical security flaw identified as CVE-2026-96667. The vulnerability manifests as a Stored Cross-Site Scripting (XSS) condition caused by improper input sanitization and output escaping within the 'first_name' parameter. Furthermore, the plugin's reCAPTCHA implementation is flawed, as it only validates the request if the 'g-recaptcha-response' parameter is present; an attacker can completely bypass this check by simply omitting the parameter from their HTTP request. This vulnerability allows an unauthenticated attacker to inject arbitrary malicious scripts, which will execute within the browser context of any user who views the affected page, leading to potential session hijacking or unauthorized administrative actions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. This may result in session theft, unauthorized account modifications, or redirection of users to malicious sites. The scope of impact is limited to sites running the vulnerable Real Estate Manager plugin version 7.3 or lower, which is widely utilized in the real estate sector.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Real Estate Manager - Property Listing and Agent Management plugin to a version released after 7.3 immediately.</li>
<li>Monitor server logs for HTTP POST requests to the plugin's submission endpoints containing script tags or JavaScript event handlers in the 'first_name' field.</li>
<li>Implement a Web Application Firewall (WAF) rule to inspect input fields for common XSS payloads, specifically targeting the 'first_name' parameter.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>xss</category><category>web-application</category><category>cve-2026-96667</category></item></channel></rss>