Impact
The Estatik Real Estate Plugin for WordPress versions before 4.3.5 fails to sanitize and escape values decoded from the get_listings request parameter before reflecting them in an unauthenticated AJAX response. This allows an attacker to inject arbitrary HTML or JavaScript, leading to a classic reflected cross‑site scripting flaw that can compromise the victim’s browser session, steal cookies, or redirect users to malicious sites.
Affected Systems
The vulnerability affects the Estatik Real Estate Plugin for WordPress versions earlier than 4.3.5. Only installations of the plugin in these versions lack the proper input filtration introduced in 4.3.5.
Risk and Exploitability
The flaw can be exploited without authentication by crafting a request to the public get_listings AJAX endpoint, as the vulnerability is described as affecting an unauthenticated response. The CVSS score of 7.1 indicates a high severity. The EPSS score of <1% and the absence of a listing in the CISA KEV catalogue suggest a relatively low probability of exploitation, yet the lack of input sanitization indicates that the vulnerability could be leveraged readily for phishing, session hijacking, or defacement when the endpoint is reachable.
OpenCVE Enrichment