Impact
The vulnerability resides in the Estatik Real Estate Plugin for WordPress versions prior to 4.3.3. In the OAuth social login process the plugin fails to bind the authentication flow to the specific user session that initiated it. An unauthenticated attacker can therefore force a victim’s browser to complete the OAuth handshake to an attacker‑controlled account. This results in the victim’s subsequent actions being recorded under and visible to that attacker, effectively enabling account takeover and data exfiltration. The weakness is a classic Cross‑Site Request Forgery flaw (CWE‑352), allowing an attacker to trigger privileged state changes on behalf of another user without proper authorization.
Affected Systems
WordPress sites utilizing the Estatik Real Estate Plugin before version 4.3.3 are affected. Site administrators should verify the installed plugin version and confirm it is 4.3.3 or later to avoid the login CSRF issue.
Risk and Exploitability
The issue carries a high impact due to the potential for unauthorized account takeover and data leakage. No EPSS score is currently available, but the lack of prerequisite conditions and the ubiquity of WordPress sites make exploitation likely in practice. The vulnerability is not listed in the CISA KEV catalog, which does not negate the need for immediate remediation.
OpenCVE Enrichment