Impact
Unauthenticated Cross Site Scripting in the Estatik WordPress plugin versions 4.3.4 and lower allows an attacker to inject arbitrary HTML or JavaScript into pages served to users. The vulnerability originates from inadequate input validation (CWE‑79). If an attacker successfully delivers malicious code, it can run in the victim’s browser, allowing session hijacking, phishing, or defacement.
Affected Systems
The affected product is the Estatik plugin for WordPress, maintained by Estatik. All releases up to and including 4.3.4 are impacted. The plugin embeds user‑supplied data directly into output without proper sanitization, creating the XSS vector.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered medium‑to‑high severity. EPSS is not available, but the lack of an exploit restriction and the unauthenticated nature of the flaw suggest a non‑trivial risk of exploitation. The vulnerability is not listed in the CISA KEV catalog, but WordPress sites that still run Estatik 4.3.4 or older should consider the damage potential. Attackers could target any public or private site running the vendor’s plugin through crafted URLs or form submissions.
OpenCVE Enrichment