Skip to main content
Vulnerability Database/CVE-2026-93908

CVE-2026-93908: Real Estate Manager WordPress Plugin XSS

CVE-2026-93908 is a stored cross-site scripting vulnerability in the Real Estate Manager WordPress plugin affecting versions up to 7.3. Authenticated attackers can inject malicious scripts via the before_price_text parameter. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-93908 Overview

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in versions up to and including 7.3. The flaw resides in the before_price_text parameter processed by the wp_ajax_rem_create_pro_ajax handler. Authenticated attackers with subscriber-level access can inject arbitrary JavaScript that executes when any user visits an affected page. The handler lacks capability, nonce, and ownership checks, allowing low-privileged accounts to reach the vulnerable code path. Because the value is stored via update_post_meta rather than post_content, the standard wp_kses filtering tied to the unfiltered_html capability does not apply.

Critical Impact

Any authenticated subscriber can persist JavaScript payloads that run in the browser context of every visitor, including administrators, enabling session theft and administrative account takeover.

Affected Products

  • Real Estate Manager – Property Listing and Agent Management plugin for WordPress
  • All versions up to and including 7.3
  • WordPress sites exposing the wp_ajax_rem_create_pro_ajax AJAX endpoint

Discovery Timeline

  • 2026-09-30 - CVE-2026-93908 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-93908

Vulnerability Analysis

The vulnerability sits in the plugin's AJAX property creation flow. The wp_ajax_rem_create_pro_ajax handler accepts submitted property data, including the before_price_text field, and writes it to post metadata without sanitization. Because the handler is registered under wp_ajax_ rather than wp_ajax_nopriv_, any authenticated user, including a subscriber, can invoke it. The plugin does not verify the user's capabilities, does not check a nonce, and does not confirm ownership of the target post. On rendering, the shortcode class outputs the stored value into the page HTML without escaping. Any script injected during creation therefore executes in the browser of every visitor who loads the property listing.

Root Cause

Three independent defects combine to produce the vulnerability. First, insufficient input sanitization in the AJAX handler accepts raw HTML and JavaScript. Second, the shortcode rendering path in classes/shortcodes.class.php emits the field without output escaping such as esc_html or esc_attr. Third, storage through update_post_meta bypasses the wp_kses filtering that WordPress normally applies to post_content for users lacking the unfiltered_html capability.

Attack Vector

An attacker registers or uses an existing subscriber account. The attacker then issues a POST request to admin-ajax.php with action=rem_create_pro_ajax and a before_price_text value containing a script payload. The absence of nonce and capability checks allows the request to succeed. When any user, including an administrator, subsequently views a page rendering the affected property listing, the injected script executes with that user's session context. Typical follow-on actions include stealing authentication cookies, creating administrator accounts, or planting further backdoors in the site.

Code-level details are documented in the plugin source at the referenced lines in classes/shortcodes.class.php and core.functions.php. See the Wordfence Vulnerability Overview and the WordPress Shortcodes Class Code for the vulnerable functions.

Detection Methods for CVE-2026-93908

Indicators of Compromise

  • POST requests to /wp-admin/admin-ajax.php with action=rem_create_pro_ajax originating from subscriber-level accounts.
  • Post meta entries with keys used by the Real Estate Manager plugin containing <script>, onerror=, onload=, or javascript: substrings.
  • Unexpected administrator accounts created shortly after a property listing view by an existing admin.
  • Outbound requests from admin browsers to unfamiliar domains immediately after loading property pages.

Detection Strategies

  • Audit the wp_postmeta table for values associated with the plugin containing HTML tags or script fragments.
  • Review web server logs for admin-ajax.php calls invoking rem_create_pro_ajax and correlate with the authenticated user role.
  • Deploy a web application firewall rule that inspects the before_price_text POST parameter for HTML and script content.

Monitoring Recommendations

  • Enable WordPress audit logging to record new user registrations, role changes, and AJAX actions.
  • Monitor for creation of new administrator accounts and modifications to wp_users and wp_usermeta.
  • Alert on any subscriber-level account invoking property creation or update AJAX endpoints.

How to Mitigate CVE-2026-93908

Immediate Actions Required

  • Update the Real Estate Manager plugin to a version later than 7.3 once the vendor releases a fix.
  • Disable user self-registration or restrict the subscriber role if the plugin cannot be updated immediately.
  • Audit existing property listings and post meta for previously injected payloads and remove them.
  • Rotate credentials for administrator accounts that may have viewed affected pages.

Patch Information

No fixed version is listed in the NVD entry at the time of publication. Monitor the Wordfence Vulnerability Overview and the plugin's WordPress.org page for a patched release. Apply the update across all sites once available.

Workarounds

  • Deactivate the Real Estate Manager plugin until a patched version is installed.
  • Block unauthenticated and subscriber access to admin-ajax.php requests carrying action=rem_create_pro_ajax at the WAF or reverse proxy.
  • Set users_can_register to false in WordPress settings to prevent attackers from provisioning subscriber accounts.
  • Apply a Content Security Policy that restricts inline script execution to reduce the impact of stored XSS payloads.
bash
# Example WAF rule (ModSecurity) to block the vulnerable AJAX action
SecRule REQUEST_URI "@contains /wp-admin/admin-ajax.php" \
  "chain,phase:2,deny,status:403,id:1029308,msg:'Block REM create_pro AJAX'"
  SecRule ARGS:action "@streq rem_create_pro_ajax"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.