Cross-Site Scripting Vulnerability in PropertyHive by Property Hive
CVE-2025-58612
6.5MEDIUM
What is CVE-2025-58612?
An improper neutralization of input during web page generation has been identified in the PropertyHive plugin, leading to a potential Stored XSS vulnerability. This flaw allows an attacker to execute arbitrary JavaScript in the context of a user's session, which can ultimately compromise sensitive user information and lead to unauthorized actions on behalf of the user. Affected versions include PropertyHive up to and including 2.1.5 and earlier versions.
Affected Version(s)
PropertyHive <= 2.1.5