CyberRota Analysis
AI-GeneratedThe Estatik Real Estate Plugin for WordPress prior to version 4.3.3 is vulnerable to a login CSRF attack, enabling unauthenticated attackers to hijack user sessions by logging victims into attacker-controlled accounts. This flaw allows attackers to access and manipulate the victim's subsequent activities, posing a significant risk to user privacy and data integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.
Original NVD Description
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.