rootpwn

high · CVSS v3 7.1 · EPSS 0.00158

CVE-2026-76790

The Estatik Real Estate Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) in versions prior to 4.3.5. This vulnerab

Overview

The Estatik Real Estate Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) in versions prior to 4.3.5. This vulnerability exists because the plugin fails to properly sanitize and escape specific request parameters before returning them in unauthenticated AJAX responses.

Description

The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.

Impact

Exploitation compromises the integrity and confidentiality of user sessions by allowing arbitrary script execution in the victim's browser. This primarily impacts site administrators and visitors who may be targeted via malicious links. Successful attacks can lead to unauthorized actions or session hijacking within the WordPress environment.

Remediation

Update the Estatik Real Estate Plugin to version 4.3.5 or later to resolve the sanitization issues. Additionally, implement a Web Application Firewall (WAF) with rulesets designed to filter and block common XSS patterns in AJAX request parameters.

Risk context

The vulnerability is rated as High severity with a CVSS v3 score of 7.1. While the EPSS score of 0.00158 indicates low current exploitation activity, the unauthenticated nature of the flaw makes it a priority for remediation on public-facing WordPress sites.

Affected products

  • WordPress
  • Estatik Real Estate Plugin < 4.3.5

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.1
CVSS v4
EPSS
0.00158

XSS WordPress Estatik AJAX Reflected XSS Plugin Security

← All CVEs