wp-property-hive CVE Vulnerabilities & CVE List (14)

Products (CPE): — CVEs: 14

wp-property-hive vulnerability overview

Aggregates CVE and security vulnerability intelligence across all wp-property-hive-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting and vendor risk csrf, with potential vendor impact session compromise across vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 114 of 14 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-0808 The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to missing or incorrect nonce validation on the "deleteexport" action. This makes it possible for unauthenticated attackers to delete property feed exports via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. [email protected] 4.3 0.10% 2025-02-12 2025-02-25
CVE-2024-12585 The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. [email protected] 6.1 1.50% 2025-01-08 2025-05-14
CVE-2024-37204 Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9. [email protected] 4.3 0.26% 2024-11-01 2025-01-29
CVE-2024-8490 The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password of an administrator account via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. [email protected] 8.8 0.31% 2024-09-17 2024-09-27
CVE-2024-35701 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13. [email protected] 6.5 0.16% 2024-06-08 2024-11-21
CVE-2024-34381 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10. [email protected] 6.5 0.18% 2024-05-06 2026-04-28
CVE-2024-3607 The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts [email protected] 4.3 0.21% 2024-05-02 2026-04-08
CVE-2024-27985 Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9. [email protected] 5.4 0.44% 2024-04-11 2026-04-28
CVE-2024-29923 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8. [email protected] 7.1 0.27% 2024-03-27 2026-04-28
CVE-2024-24718 Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6. [email protected] 4.3 0.12% 2024-03-26 2026-04-28
CVE-2024-23513 Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5. [email protected] 8.7 0.54% 2024-02-12 2026-04-28
CVE-2023-22706 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions. [email protected] 7.1 0.20% 2023-05-15 2024-11-21
CVE-2023-29172 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions. [email protected] 7.1 0.20% 2023-04-07 2024-11-21
CVE-2018-6465 The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php. [email protected] 6.1 0.74% 2018-01-31 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence