CVE-2026-66578: WordPress PropertyHive plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability
Published Sep 17, 2026
·Updated
Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
Affected Software
1 affected component
WordPress PropertyHive plugin<=2.2.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress PropertyHive pluginto a version that resolves this vulnerability.Fixed in 2.3.0
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Contributor-level access to a WordPress site using an affected PropertyHive version. Exploitation also requires user interaction.
2
Which installations are affected?
PropertyHive versions 2.2.6 and earlier are affected. The provided data does not state whether a default configuration changes exposure.
3
What is the potential impact?
Successful exploitation may allow cross-site scripting with low impact to confidentiality, integrity, and availability. The scope is changed, meaning the impact can extend beyond the vulnerable component's authorization boundary.