CVE-2024-13347: Smartdatasoft Essential Wp Real Estate
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
Affected products
- Smartdatasoft Essential Wp Real Estate: up to and including 1.1.3
Published 2025-02-03. Last modified 2026-06-17.