Executive brief
The Estatik Real Estate Plugin for WordPress contains a reflected cross-site scripting vulnerability in its AJAX endpoint that allows unauthenticated attackers to inject malicious scripts into web pages viewed by other users. By crafting a malicious link, an attacker can steal user session tokens, redirect users to fraudulent sites, or modify the appearance of property listings to perpetrate phishing attacks. The vulnerability affects all versions before 4.3.5 and requires no user privileges or authentication.
Technical details
The plugin fails to sanitize and escape values decoded from the get_listings request parameter before echoing them back in an unauthenticated AJAX response, resulting in reflected XSS (CWE-79). Attack vector is network-based and requires no authentication or user interaction beyond clicking a crafted link. A patch is available in version 4.3.5 and later.
Affected products
- Estatik Real Estate Plugin before 4.3.5
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: version 4.3.5