WordPress security by component
PropertyHive
Plugin description
PropertyHive is a WordPress component with 19 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
propertyhiveLatest vulnerability
CVE-2026-57381: PropertyHive: Cross-site scripting
PropertyHive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.2.3.
| Safe version |
|
||
|---|---|---|---|
| Jul 13, 2026 |
CVE-2026-57381
PropertyHive: Cross-site scripting
PropertyHive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.2.3.
|
2.2.4 |
CVE7.1
NVDPending
|
| May 27, 2026 |
CVE-2026-42729
PropertyHive: Cross-site scripting
PropertyHive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.2.2.
|
2.2.3 |
CVE7.1
NVDPending
|
| Dec 18, 2025 |
CVE-2025-66088
PropertyHive: A security weakness
PropertyHive is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Nov 21, 2025 |
CVE-2025-66087
PropertyHive: A security weakness
PropertyHive is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 03, 2025 |
CVE-2025-58612
PropertyHive: Cross-site scripting
PropertyHive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 16, 2025 |
CVE-2025-39577
PropertyHive: Cross-site scripting
PropertyHive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 08, 2025 |
CVE-2024-12585
Property Hive: Cross-site scripting
Property Hive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Nov 01, 2024 |
CVE-2024-37204
PropertyHive: A security weakness
PropertyHive is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Sep 17, 2024 |
CVE-2024-8490
PropertyHive: Cross-site request forgery
PropertyHive is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD6.5
|
| Jun 08, 2024 |
CVE-2024-35701
PropertyHive: Cross-site scripting
PropertyHive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| May 06, 2024 |
CVE-2024-34381
PropertyHive: Cross-site scripting
PropertyHive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| May 02, 2024 |
CVE-2024-3607
PropertyHive: A security weakness
PropertyHive is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 11, 2024 |
CVE-2024-27985
PropertyHive: Code execution
PropertyHive is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Mar 27, 2024 |
CVE-2024-29923
PropertyHive: Cross-site scripting
PropertyHive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Mar 26, 2024 |
CVE-2024-24718
PropertyHive: A security weakness
PropertyHive is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD6.5
|
| Feb 12, 2024 |
CVE-2024-23513
PropertyHive: Code execution
PropertyHive is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.7
NVD9.8
|
| May 15, 2023 |
CVE-2023-22706
Propertyhive: Cross-site scripting
Propertyhive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Apr 07, 2023 |
CVE-2023-29172
Propertyhive: Cross-site scripting
Propertyhive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Jan 31, 2018 |
CVE-2018-6465
Propertyhive: Cross-site scripting
Propertyhive is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|