CVE-2026-76790: Unknown Estatik Real Estate Plugin
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.
Affected products
- Unknown Estatik Real Estate Plugin: from 4.0.1, before 4.3.5 (fixed in 4.3.5)
Published 2026-09-19. Last modified 2026-09-21.