CVE-2026-16262: Estatik < 4.3.3 - Login CSRF
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16262?
CVE-2026-16262 has a risk score of 43, indicating a moderate level of severity.
How do I fix CVE-2026-16262?
To fix CVE-2026-16262, update the Estatik Real Estate Plugin to version 4.3.3 or later.
What type of vulnerability is CVE-2026-16262?
CVE-2026-16262 is categorized as a Login CSRF (Cross-Site Request Forgery) vulnerability.
Who is affected by CVE-2026-16262?
Users of the Estatik Real Estate Plugin for WordPress prior to version 4.3.3 are affected by CVE-2026-16262.
What impact does CVE-2026-16262 have on users?
CVE-2026-16262 allows an unauthenticated attacker to log a victim into an attacker-controlled account, compromising user activity.