VYPR
Medium severity6.4NVD Advisory· Published Jun 4, 2026· Updated Jun 4, 2026

CVE-2019-25742

CVE-2019-25742

Description

WordPress Theme Zoner Real Estate 4.1.1 has a persistent XSS vulnerability allowing authenticated agents to inject scripts via the Address field, leading to session hijacking.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

WordPress Theme Zoner Real Estate 4.1.1 has a persistent XSS vulnerability allowing authenticated agents to inject scripts via the Address field, leading to session hijacking.

Vulnerability

WordPress Theme Zoner Real Estate versions up to and including 4.1.1 contain a persistent cross-site scripting (XSS) vulnerability. This flaw resides in the Address input field used when creating properties. The vulnerability allows authenticated agents to inject malicious scripts that are stored persistently within the application.

Exploitation

An attacker with agent-level authentication can inject JavaScript payloads into the Address field when creating or editing a property. These scripts are designed to execute when an administrator views the property for approval. No other user interaction is required beyond the initial injection by the authenticated agent.

Impact

Successful exploitation of this vulnerability allows an attacker to achieve cookie theft and session hijacking. When an administrator views the compromised property, the injected JavaScript executes in their browser context, potentially allowing the attacker to impersonate the administrator or gain unauthorized access to their account.

Mitigation

There is no specific patched version or release date disclosed in the available references. Users are advised to check for updates from the theme developer. As of the available information, no workarounds or specific mitigation steps beyond updating the theme when a patch becomes available have been published. The theme is listed as affecting versions <= 4.1.1 [1].

AI Insight generated on Jun 4, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

4

News mentions

0

No linked articles in our index yet.