Medium severity6.8NVD Advisory· Published Feb 3, 2025· Updated Jun 17, 2026
CVE-2024-13347
CVE-2024-13347
Description
The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:smartdatasoft:essential_wp_real_estate:*:*:*:*:*:wordpress:*:*Range: <=1.1.3
- Range: <=1.1.3
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/e2f97636-4c67-409a-83c6-ad6255aa2cc5/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.