PT-2026-68871 · WordPress · Estatik Real Estate
CVE-2026-16262
·
Published
2026-08-07
·
Updated
2026-08-07
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Estatik Real Estate Plugin WordPress plugin versions prior to 4.3.3
Description
The plugin fails to bind its OAuth social login flow to the initiating user session. This allows an unauthenticated attacker to perform a login CSRF (Cross-Site Request Forgery), which forces a victim to log into an account controlled by the attacker. Consequently, any subsequent activity performed by the victim is stored in and accessible to the attacker's account.
Recommendations
Update the Estatik Real Estate Plugin WordPress plugin to version 4.3.3 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Estatik Real Estate