Executive brief
Estatik is a WordPress plugin for creating property listings and real estate websites. An unauthenticated cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts that can steal visitor data, hijack user accounts, or deface website content without requiring any special privileges or authentication.
Technical details
A cross-site scripting (XSS) vulnerability exists in the Estatik WordPress plugin version 4.3.4 and below, allowing unauthenticated attackers to inject malicious JavaScript into web pages. The vulnerability requires user interaction—such as a victim clicking a malicious link or visiting a specially crafted page—for successful exploitation. An attacker can leverage this to steal session cookies, capture form data, perform actions on behalf of the victim, or redirect users to phishing sites. As of the advisory publication date, no official patch was available; Patchstack offered a WAF mitigation rule as a temporary measure.
Affected products
- Estatik Estatik <= 4.3.4
Timeline
- 2026-09-02: disclosed: Published to NVD and Patchstack
- 2026-03-30: other: Reported by Neelakandan A