PatchSiren cyber security CVE debrief
CVE-2026-65560 Property Hive CVE debrief
CVE-2026-65560 is an unauthenticated Cross Site Scripting (XSS) vulnerability in Houzez Property Feed plugin version 2.5.48 or earlier. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. This vulnerability could allow attackers to inject malicious scripts into web pages viewed by users of the Houzez Property Feed plugin. WordPress administrators and users of the Houzez Property Feed plugin should be aware of this vulnerability and take steps to verify and mitigate it. The CVE record was published on 2026-08-06T15:17:18.060Z and has not been modified since then.
- Vendor
- Property Hive
- Product
- Houzez Property Feed
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
WordPress administrators and users of the Houzez Property Feed plugin should be aware of this vulnerability and take steps to verify and mitigate it. Defenders should prioritize verifying the presence of Houzez Property Feed plugin version 2.5.48 or earlier in their WordPress installations and consider updating to a patched version if available.
Technical summary
CVE-2026-65560 is an unauthenticated Cross Site Scripting (XSS) vulnerability in Houzez Property Feed plugin version 2.5.48 or earlier. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. This vulnerability could allow attackers to inject malicious scripts into web pages viewed by users of the Houzez Property Feed plugin.
Defensive priority
Defenders should prioritize verifying the presence of Houzez Property Feed plugin version 2.5.48 or earlier in their WordPress installations and consider updating to a patched version if available.
Recommended defensive actions
- Verify the presence of Houzez Property Feed plugin version 2.5.48 or earlier in WordPress installations.
- Consider updating to a patched version if available.
- Monitor for suspicious activity related to the Houzez Property Feed plugin.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
Evidence is limited; primary official records indicate an unauthenticated Cross Site Scripting (XSS) vulnerability in Houzez Property Feed plugin version 2.5.48 or earlier. Further verification is needed to determine the full scope of affected systems. Defenders should verify the presence of Houzez Property Feed plugin version 2.5.48 or earlier in their WordPress installations and consider updating to a patched version if available.
Official resources
-
CVE-2026-65560 CVE record
CVE.org
-
CVE-2026-65560 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:18.060Z and has not been modified since then.