CVE-2026-81775
moderateUnauthenticated XSS in Estatik WordPress Plugin (versions up to 4.3.4)
CVE-2026-81775 is an unauthenticated cross-site scripting (XSS) flaw in the Estatik real estate plugin for WordPress, affecting all versions up to and including 4.3.4. Because no authentication is required, an unauthenticated attacker can supply crafted input that the plugin processes, causing attacker-controlled JavaScript to execute in the browser of a user who views the affected page. Successful exploitation could lead to theft of session cookies, redirects to attacker-controlled content, or unwanted actions performed in the context of the affected site, with impact limited to low confidentiality, integrity and availability per the CVSS 7.1 score. Any WordPress site running Estatik 4.3.4 or earlier is affected, with the greatest risk on sites where public visitors can submit data that the plugin renders on public pages. No public proof-of-concept, CISA KEV listing, or reports of in-the-wild exploitation are known, and EPSS currently estimates only a 0.2% probability of exploitation within 30 days.
What to do: Update the Estatik plugin to the latest release (any version newer than 4.3.4) as soon as the patched version is available. In the meantime, review listing data, custom fields, and plugin settings for injected scripts, and watch for unexpected administrator accounts or modified content. No public exploit exists, so patching promptly is the primary action.
| Estatik (WordPress real estate plugin) | <= 4.3.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.