๐Ÿ” CVE Alert

CVE-2026-76790

UNKNOWN 0.0

Estatik < 4.3.5 - Reflected XSS via get_listings hash Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.

Vendor unknown
Product estatik real estate plugin
Published Sep 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown estatik real estate plugin

Be the first to know when new unknown vulnerabilities affecting unknown estatik real estate plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Estatik Real Estate Plugin
4.0.1 < 4.3.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b722c7e9-7c8b-4510-85af-075b1bba9d66/

Credits

Morato Antoine WPScan