plugin

Estatik Vulnerabilities

9 known security issues reported for the Estatik WordPress plugin. Most recent disclosed Aug 20, 2026.

2 critical 2 high 5 medium

Running Estatik on your site? Check whether your installed version is affected.

Scan your site free

Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Mail Relay

medium

The Estatik Real Estate Plugin plugin for WordPress is vulnerable to mail relay in all versions up to 4.3.4 (exclusive). This makes it possible for unauthenticated attackers to send emails to arbitrary recipients from the server.

CVSS:
5.3
Affected:
up to 4.3.4
Fixed in:
4.3.4
Disclosed:
Aug 20, 2026

CVE-2026-18044 on NVD →

Estatik <= 4.3.2 - Cross-Site Request Forgery

medium

The Estatik plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a s...

CVSS:
4.3
Affected:
up to 4.3.2
Fixed in:
4.3.3
Disclosed:
Aug 3, 2026

CVE-2026-16262 on NVD →

Estatik <= 4.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Estatik plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 4.1.13
Fix:
No patched version reported
Disclosed:
Oct 16, 2025

CVE-2025-62963 on NVD →

Estatik <= 4.3.1 - Authenticated (Contributor+) Local File Inclusion

high

The Estatik plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.3.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This c...

CVSS:
8.8
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
Feb 23, 2025

CVE-2025-26905 on NVD →

Estatik Real Estate Plugin <= 4.1.0 - Reflected Cross-Site Scripting

medium

The Estatik Real Estate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add/remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Jan 25, 2024

CVE-2023-6050 on NVD →

Estatik Real Estate Plugin <= 4.1.0 - Unauthenticated PHP Object Injection

critical

The Estatik Real Estate Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.0 via deserialization of untrusted input through cookies. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If...

CVSS:
9.8
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Dec 25, 2023

CVE-2023-6049 on NVD →

Estatik Real Estate Plugin <= 4.1.0 - Missing Authorization to Limited Arbitrary Options Update

medium

The Estatik Real Estate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the es_dismiss_notices() function in all versions up to, and including, 4.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update...

CVSS:
5.4
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Dec 25, 2023

CVE-2023-6048 on NVD →

Estatik <= 2.2.5 - Unauthenticated Arbitrary File Upload

critical

The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php.

CVSS:
9.8
Affected:
up to 2.3.0
Fixed in:
2.3.1
Disclosed:
Aug 1, 2016

CVE-2016-10958 on NVD →

Estatik <= 2.3.0 - Cross-Site Request Forgery to Arbitrary File Upload

high

The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php.

CVSS:
8.8
Affected:
up to 2.3.0
Fixed in:
2.3.1
Disclosed:
Aug 1, 2016

CVE-2016-10959 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database