WP Property Hive is a developer of real-estate listing and property management plugins for WordPress, with a modest but focused vulnerability footprint concentrated in its PropertyHive and Houzez Property Feed products. The reported issues reflect integration and input-handling challenges typical of WordPress plugin ecosystems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Property Hive over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23513CRITICAL Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5. | Feb 12, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-12585MEDIUM The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which co | Jan 8, 2025 | 6.1 | 24 | NO | YES |
CVE-2024-27985HIGH Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9. | Apr 11, 2024 | 8.8 | 23 | NO | NO |
CVE-2018-6465MEDIUM The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php. | Jan 31, 2018 | 6.1 | 22 | NO | NO |
CVE-2023-22706MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions. | May 15, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-29172MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions. | Apr 7, 2023 | 6.1 | 21 | NO | NO |
CVE-2024-8490MEDIUM The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation | Sep 17, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-24718MEDIUM Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6. | Mar 26, 2024 | 6.5 | 20 | NO | NO |
CVE-2025-0808MEDIUM The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to missing or incorrect nonce va | Feb 12, 2025 | 5.4 | 19 | NO | NO |
CVE-2024-34381MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a throu | May 6, 2024 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Property Hive.
Media articles that mention a CVE ID that affects a product developed by Wp Property Hive — matched by CVE ID, not by vendor name.