Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesEstatik Real Estate Plugin

Estatik Real Estate Plugin vulnerabilities

Estatik Real Estate Plugin has 9 known vulnerabilities in this database. The most recent published record is dated 19 Sep 2026.

Known vulnerabilities
9
Active installs
10,000+
Latest version
4.3.6
Last updated
22 Sep 2026
Most recent
19 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-76790
High 7.1Before 4.3.5Fixed in 4.3.519 Sep 2026
Security weakness
CVE-2026-18044
Low 3.7Before 4.3.4Fixed in 4.3.412 Aug 2026
Cross-site request forgery (CSRF)
CVE-2026-16262
High 7.5Before 4.3.3Fixed in 4.3.37 Aug 2026
Authentication bypass
CVE-2026-14547
Medium 5.3Before 4.3.3Fixed in 4.3.36 Aug 2026
Broken access control
CVE-2023-6048
Medium 6.5Before 4.1.1Fixed in 4.1.115 Jan 2024
PHP object injection
CVE-2023-6049
Critical 9.8Before 4.1.1Fixed in 4.1.115 Jan 2024
Cross-site scripting (XSS)
CVE-2023-6050
Medium 6.1Before 4.1.1Fixed in 4.1.115 Jan 2024
Arbitrary file upload
CVE-2016-10958
High 7.5Before 2.3.0Fixed in 2.3.016 Sep 2019
Cross-site request forgery (CSRF)
CVE-2016-10959
Medium 6.5Before 2.3.1Fixed in 2.3.116 Sep 2019
Read the published descriptions
CVE-2026-76790, 19 Sep 2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting. CVE record
CVE-2026-18044, 12 Aug 2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is configured to route to a custom address. CVE record
CVE-2026-16262, 7 Aug 2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker. CVE record
CVE-2026-14547, 6 Aug 2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing. CVE record
CVE-2023-6048, 15 Jan 2024
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of the site's options to 1, which could be used to break sites and lead to DoS when certain options are reset CVE record
CVE-2023-6049, 15 Jan 2024
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog CVE record
CVE-2023-6050, 15 Jan 2024
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin CVE record
CVE-2016-10958, 16 Sep 2019
The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php. CVE record
CVE-2016-10959, 16 Sep 2019
The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php. CVE record

What to do if you run Estatik Real Estate Plugin

If you run Estatik Real Estate Plugin, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Estatik Real Estate Plugin vulnerabilities

Free. We email you when a new vulnerability is published for Estatik Real Estate Plugin, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support