CVE-2019-25742
Description
WordPress Theme Zoner Real Estate 4.1.1 has a persistent XSS vulnerability allowing authenticated agents to inject scripts via the Address field, leading to session hijacking.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
WordPress Theme Zoner Real Estate 4.1.1 has a persistent XSS vulnerability allowing authenticated agents to inject scripts via the Address field, leading to session hijacking.
Vulnerability
WordPress Theme Zoner Real Estate versions up to and including 4.1.1 contain a persistent cross-site scripting (XSS) vulnerability. This flaw resides in the Address input field used when creating properties. The vulnerability allows authenticated agents to inject malicious scripts that are stored persistently within the application.
Exploitation
An attacker with agent-level authentication can inject JavaScript payloads into the Address field when creating or editing a property. These scripts are designed to execute when an administrator views the property for approval. No other user interaction is required beyond the initial injection by the authenticated agent.
Impact
Successful exploitation of this vulnerability allows an attacker to achieve cookie theft and session hijacking. When an administrator views the compromised property, the injected JavaScript executes in their browser context, potentially allowing the attacker to impersonate the administrator or gain unauthorized access to their account.
Mitigation
There is no specific patched version or release date disclosed in the available references. Users are advised to check for updates from the theme developer. As of the available information, no workarounds or specific mitigation steps beyond updating the theme when a patch becomes available have been published. The theme is listed as affecting versions <= 4.1.1 [1].
AI Insight generated on Jun 4, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2=4.1.1+ 1 more
- (no CPE)range: =4.1.1
- (no CPE)range: =4.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
4News mentions
0No linked articles in our index yet.