Wp-property-hiveCVEs & Vulnerabilities

14 CVEs affecting Wp-property-hive products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

propertyhive 13houzez property feed 1
CVE-2025-0808MEDIUM

The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to missing or incorrect nonce validation on the "deleteexport" action. This makes it possible for unauthenticated attackers to delete property feed exports via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

12 Feb 2025
5.4
CVSS
CVE-2024-12585MEDIUM

The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

8 Jan 2025
6.1
CVSS
CVE-2024-37204MEDIUM

Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.

1 Nov 2024
4.3
CVSS
CVE-2024-8490MEDIUM

The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password of an administrator account via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

17 Sep 2024
6.5
CVSS
CVE-2024-35701MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13.

8 Jun 2024
5.4
CVSS
CVE-2024-34381MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.

6 May 2024
5.4
CVSS
CVE-2024-3607MEDIUM

The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts

2 May 2024
4.3
CVSS
CVE-2024-27985HIGH

Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9.

11 Apr 2024
8.8
CVSS
CVE-2024-29923MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8.

27 Mar 2024
6.1
CVSS
CVE-2024-24718MEDIUM

Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.

26 Mar 2024
6.5
CVSS
CVE-2024-23513CRITICAL

Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.

12 Feb 2024
9.8
CVSS
CVE-2023-22706MEDIUM

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions.

15 May 2023
6.1
CVSS
CVE-2023-29172MEDIUM

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions.

7 Apr 2023
6.1
CVSS
CVE-2018-6465MEDIUM

The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.

31 Jan 2018
6.1
CVSS
← PrevPage 1 / 1Next →
Wp-property-hive CVEs & Vulnerabilities — 14 Tracked