Description
The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.
Published: 2026-09-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The Estatik Real Estate Plugin for WordPress versions before 4.3.5 fails to sanitize and escape values decoded from the get_listings request parameter before reflecting them in an unauthenticated AJAX response. This allows an attacker to inject arbitrary HTML or JavaScript, leading to a classic reflected cross‑site scripting flaw that can compromise the victim’s browser session, steal cookies, or redirect users to malicious sites.

Affected Systems

The vulnerability affects the Estatik Real Estate Plugin for WordPress versions earlier than 4.3.5. Only installations of the plugin in these versions lack the proper input filtration introduced in 4.3.5.

Risk and Exploitability

The flaw can be exploited without authentication by crafting a request to the public get_listings AJAX endpoint, as the vulnerability is described as affecting an unauthenticated response. The CVSS score of 7.1 indicates a high severity. The EPSS score of <1% and the absence of a listing in the CISA KEV catalogue suggest a relatively low probability of exploitation, yet the lack of input sanitization indicates that the vulnerability could be leveraged readily for phishing, session hijacking, or defacement when the endpoint is reachable.

Generated by OpenCVE AI on September 20, 2026 at 00:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Estatik Real Estate Plugin to version 4.3.5 or newer, which implements proper sanitization for the get_listings hash parameter.
  • Block or disable public access to the get_listings AJAX endpoint using a web‑application firewall or a WordPress security plugin that rejects unauthenticated requests to that endpoint.
  • Add a Content Security Policy that disallows inline scripts or restricts script sources, or apply server‑side escaping to the reflected value for legacy installations.

Generated by OpenCVE AI on September 20, 2026 at 00:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions estatik
Vendors & Products Wordpress-extensions
Wordpress-extensions estatik

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Sat, 19 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.
Title Estatik < 4.3.5 - Reflected XSS via get_listings hash Parameter
References

Subscriptions

Wordpress-extensions Estatik
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:20:11.208Z

Reserved: 2026-08-19T17:55:39.906Z

Link: CVE-2026-76790

cve-icon Vulnrichment

Updated: 2026-09-19T13:13:11.401Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:32.650

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-76790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:38Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')