CVE-2026-81775: WordPress Estatik plugin <= 4.3.4 - Cross Site Scripting (XSS) vulnerability
Published Sep 2, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
Affected Software
1 affected component
WordPress Estatik plugin<=4.3.4
Event History
Sep 2, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or plugin privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
2
What impact could successful exploitation have?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. This means successful exploitation may affect a security authority beyond the vulnerable plugin's own context.
3
Which plugin versions are affected?
Estatik versions 4.3.4 and earlier are identified as affected. The provided data does not identify a fixed version.