CVE-2026-96350: WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability
Published Sep 30, 2026
·Updated
Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
Affected Software
1 affected component
Estatik Estatik<=4.3.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Estatik pluginto a version that resolves this vulnerability.Fixed in 4.3.6
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker can exploit it remotely without authentication or user interaction, as indicated by the network attack vector, no required privileges, and no user interaction requirement.
2
What is the likely impact of successful exploitation?
Successful exploitation can result in privilege escalation and has high impact on confidentiality, integrity, and availability. An attacker may gain elevated access within the affected WordPress environment.
3
Which installations are affected?
Estatik plugin versions 4.3.5 and earlier are affected.