CVE-2026-76790
Estatik < 4.3.5 - Reflected XSS via get_listings hash Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.
| Vendor | unknown |
| Product | estatik real estate plugin |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown estatik real estate plugin
Be the first to know when new unknown vulnerabilities affecting unknown estatik real estate plugin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Estatik Real Estate Plugin
4.0.1 < 4.3.5
References
Credits
Morato Antoine WPScan