PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65560 Property Hive CVE debrief

CVE-2026-65560 is an unauthenticated Cross Site Scripting (XSS) vulnerability in Houzez Property Feed plugin version 2.5.48 or earlier. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. This vulnerability could allow attackers to inject malicious scripts into web pages viewed by users of the Houzez Property Feed plugin. WordPress administrators and users of the Houzez Property Feed plugin should be aware of this vulnerability and take steps to verify and mitigate it. The CVE record was published on 2026-08-06T15:17:18.060Z and has not been modified since then.

Vendor
Property Hive
Product
Houzez Property Feed
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

WordPress administrators and users of the Houzez Property Feed plugin should be aware of this vulnerability and take steps to verify and mitigate it. Defenders should prioritize verifying the presence of Houzez Property Feed plugin version 2.5.48 or earlier in their WordPress installations and consider updating to a patched version if available.

Technical summary

CVE-2026-65560 is an unauthenticated Cross Site Scripting (XSS) vulnerability in Houzez Property Feed plugin version 2.5.48 or earlier. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. This vulnerability could allow attackers to inject malicious scripts into web pages viewed by users of the Houzez Property Feed plugin.

Defensive priority

Defenders should prioritize verifying the presence of Houzez Property Feed plugin version 2.5.48 or earlier in their WordPress installations and consider updating to a patched version if available.

Recommended defensive actions

  • Verify the presence of Houzez Property Feed plugin version 2.5.48 or earlier in WordPress installations.
  • Consider updating to a patched version if available.
  • Monitor for suspicious activity related to the Houzez Property Feed plugin.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence is limited; primary official records indicate an unauthenticated Cross Site Scripting (XSS) vulnerability in Houzez Property Feed plugin version 2.5.48 or earlier. Further verification is needed to determine the full scope of affected systems. Defenders should verify the presence of Houzez Property Feed plugin version 2.5.48 or earlier in their WordPress installations and consider updating to a patched version if available.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:18.060Z and has not been modified since then.