PT-2026-46212 · Fruitfulcode · Zoner Real Estate

M0Ze

·

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2019-25742

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when creating properties. Attackers can inject JavaScript payloads in the property creation form that execute when administrators view the property for approval, enabling cookie theft and session hijacking.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25742

Affected Products

Zoner Real Estate