AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16262

HIGH · CVSS 7.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Estatik Real Estate Plugin for WordPress prior to version 4.3.3 is vulnerable to a login CSRF attack, enabling unauthenticated attackers to hijack user sessions by logging victims into attacker-controlled accounts. This flaw allows attackers to access and manipulate the victim's subsequent activities, posing a significant risk to user privacy and data integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-16262
Severity
HIGH
CVSS
7.5
EPSS
0.16%
WordPress

Original NVD Description

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.