HomeWordPress vulnerabilitiesEstatik Real Estate Plugin
Estatik Real Estate Plugin vulnerabilities
Estatik Real Estate Plugin has 9 known vulnerabilities in this database. The most recent published record is dated 19 Sep 2026.
- Known vulnerabilities
- 9
- Active installs
- 10,000+
- Latest version
- 4.3.6
- Last updated
- 22 Sep 2026
- Most recent
- 19 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-76790 | High 7.1 | Before 4.3.5 | Fixed in 4.3.5 | 19 Sep 2026 |
| Security weakness CVE-2026-18044 | Low 3.7 | Before 4.3.4 | Fixed in 4.3.4 | 12 Aug 2026 |
| Cross-site request forgery (CSRF) CVE-2026-16262 | High 7.5 | Before 4.3.3 | Fixed in 4.3.3 | 7 Aug 2026 |
| Authentication bypass CVE-2026-14547 | Medium 5.3 | Before 4.3.3 | Fixed in 4.3.3 | 6 Aug 2026 |
| Broken access control CVE-2023-6048 | Medium 6.5 | Before 4.1.1 | Fixed in 4.1.1 | 15 Jan 2024 |
| PHP object injection CVE-2023-6049 | Critical 9.8 | Before 4.1.1 | Fixed in 4.1.1 | 15 Jan 2024 |
| Cross-site scripting (XSS) CVE-2023-6050 | Medium 6.1 | Before 4.1.1 | Fixed in 4.1.1 | 15 Jan 2024 |
| Arbitrary file upload CVE-2016-10958 | High 7.5 | Before 2.3.0 | Fixed in 2.3.0 | 16 Sep 2019 |
| Cross-site request forgery (CSRF) CVE-2016-10959 | Medium 6.5 | Before 2.3.1 | Fixed in 2.3.1 | 16 Sep 2019 |
Read the published descriptions
- CVE-2026-76790, 19 Sep 2026
- The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting. CVE record
- CVE-2026-18044, 12 Aug 2026
- The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is configured to route to a custom address. CVE record
- CVE-2026-16262, 7 Aug 2026
- The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker. CVE record
- CVE-2026-14547, 6 Aug 2026
- The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing. CVE record
- CVE-2023-6048, 15 Jan 2024
- The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of the site's options to 1, which could be used to break sites and lead to DoS when certain options are reset CVE record
- CVE-2023-6049, 15 Jan 2024
- The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog CVE record
- CVE-2023-6050, 15 Jan 2024
- The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin CVE record
- CVE-2016-10958, 16 Sep 2019
- The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php. CVE record
- CVE-2016-10959, 16 Sep 2019
- The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php. CVE record
What to do if you run Estatik Real Estate Plugin
If you run Estatik Real Estate Plugin, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Estatik Real Estate Plugin vulnerabilities
Free. We email you when a new vulnerability is published for Estatik Real Estate Plugin, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.