WordPress PropertyHive Plugin <= 1.5.48 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-22706
7.1HIGH
What is CVE-2023-22706?
An unauthenticated reflected Cross-Site Scripting (XSS) vulnerability exists in the PropertyHive plugin versions up to 1.5.48. This flaw allows attackers to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized access to user sessions and data. Prompt updates and security measures are recommended to mitigate exploit risks.
Affected Version(s)
PropertyHive <= 1.5.48