Reality [reality] < 2.5.6
unknownMultiple Reflected Cross-Site Scripting (XSS) vulnerabilities found by Vlad Vector in WordPress Reality premium theme (versions <= 2.5.5).
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
- Disclosed:
- Jul 29, 2020
theme
11 known security issues reported for the Reality WordPress theme. Most recent disclosed Jul 29, 2020.
Running Reality on your site? Check whether your installed version is affected.
Scan your site freeMultiple Reflected Cross-Site Scripting (XSS) vulnerabilities found by Vlad Vector in WordPress Reality premium theme (versions <= 2.5.5).
The Reality theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on the 'keyword' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
The Reality | Estate Multipurpose WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'label' & 'tab' parameters in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...
The Reality theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on the 'keyword' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
The Reality | Estate Multipurpose WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'label' & 'tab' parameters in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by m0ze in WordPress Reality premium theme (versions <= 2.5.1).
The Reality theme for WordPress is vulnerable to Stored Cross-Site Scripting via the property and user pages in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute w...
The Reality theme for WordPress is vulnerable to Stored Cross-Site Scripting via the property and user pages in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute w...
----[]- Persistent XSS on any property page: -[]---- Vulnerable input fields: 1 - Description & Price -> 'PRICE POSTFIX TEXT' and 'SECOND PRICE POSTFIX TEXT'; 2 - Additional Information -> 'TITLE' and 'VALUE'; 3 - Location & Map -> 'ADDRESS *'. P...
Reflected XSS was discovered in the «Reality | Estate Multipurpose WordPress Theme», tested version — v2.5.1 Edit (WPScanTeam): January 16th, 2020 - Report Received & Envato Contacted January 17th, 2020 - Envato Investigating February 6th, 2020 - Envato Contacted Again for Updates February...
An Unauthenticated & Authenticated Reflected XSS vulnerabilities was discovered in the Reality theme through 2.5.3 and 2.5.5 for WordPress.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free