CVE-2026-25369

WordPress Flexmls® IDX plugin <= 3.15.9 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Reflected XSS.This issue affects Flexmls® IDX: from n/a through <= 3.15.9.


We have discovered 528 live websites that are affected by CVE-2026-25369.

Run a Free Instant Scan




Affected Software

Product  Flexmls Idx
Category Wordpress Plugins
Vulnerable Domains528 live websites (75% of Flexmls Idx install base)
Vulnerable Versions
  • from 0 through 3.15.9
Vulnerable Versions Count37 versions ( 95% of all versions)



Details

  • Published - Mar 16, 2026
  • Updated - Apr 1, 2026

Credits

  • Riski Gana Prasetya | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-25369
United States495 websites



Mexico14 websites
Germany7 websites
Bulgaria2 websites
GB2 websites
Canada1 websites
Cyprus1 websites
France1 websites
Portugal1 websites

Website Distribution by TLD

Number of websites using CVE-2026-25369
.com501 websites
.net15 websites
.info2 websites
.org2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-25369

Top websites that are affected by CVE-2026-25369. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***,***
*******************************.com United States*,***,***
*********************.com United States*,***,***
****************.com United States*,***,***
***************.com United States*,***,***
**************.com United States*,***,***
*****************.com United States*,***,***
***********************.com United States*,***,***
**************.com United States*,***,***
*************************.com United States*,***,***
See full domain list

FAQ

A total of 528 websites have been identified as vulnerable to CVE-2026-25369, based on global website indexing conducted by WebTechSurvey.
The Flexmls Idx is affected by the CVE-2026-25369 vulnerability.
Flexmls Idx versions up to and including 3.15.9 are vulnerable to CVE-2026-25369.