CVE-2026-16262: CWE-352 Cross-Site Request Forgery (CSRF) in Estatik Real Estate Plugin
CVE-2026-16262 is a Cross-Site Request Forgery (CSRF) vulnerability in the Estatik Real Estate Plugin for WordPress before version 4.3.3. The flaw allows an unauthenticated attacker to log a victim into an attacker-controlled account by exploiting the OAuth social login flow, which is not properly bound to the initiating user session. This causes the victim's subsequent activity to be associated with and accessible by the attacker. The vulnerability has a high severity rating with a CVSS score of 7.5.
AI Analysis
Technical Summary
The Estatik Real Estate Plugin for WordPress versions prior to 4.3.3 contains a CSRF vulnerability (CWE-352) in its OAuth social login implementation. Because the plugin does not bind the OAuth login flow to the initiating user session, an attacker can trick a victim into logging into an attacker-controlled account without their consent. This login CSRF enables the attacker to have the victim's actions recorded under the attacker's account, potentially exposing sensitive user activity data. No official patch or remediation level has been confirmed in the provided data.
Potential Impact
An attacker can cause a victim to be logged into an attacker-controlled account, leading to the victim's actions being recorded and accessible by the attacker. This compromises user session integrity and privacy but does not directly disclose confidential data or allow privilege escalation. The impact is rated high due to the potential for misuse of user sessions and data exposure.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider disabling the OAuth social login feature or applying any recommended temporary mitigations from the vendor. Monitor official Estatik plugin channels for updates.
CVE-2026-16262: CWE-352 Cross-Site Request Forgery (CSRF) in Estatik Real Estate Plugin
Description
CVE-2026-16262 is a Cross-Site Request Forgery (CSRF) vulnerability in the Estatik Real Estate Plugin for WordPress before version 4.3.3. The flaw allows an unauthenticated attacker to log a victim into an attacker-controlled account by exploiting the OAuth social login flow, which is not properly bound to the initiating user session. This causes the victim's subsequent activity to be associated with and accessible by the attacker. The vulnerability has a high severity rating with a CVSS score of 7.5.
CVSS v3.1
Score 7.5high
Affected software
Estatik Real Estate Plugin
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Estatik Real Estate Plugin for WordPress versions prior to 4.3.3 contains a CSRF vulnerability (CWE-352) in its OAuth social login implementation. Because the plugin does not bind the OAuth login flow to the initiating user session, an attacker can trick a victim into logging into an attacker-controlled account without their consent. This login CSRF enables the attacker to have the victim's actions recorded under the attacker's account, potentially exposing sensitive user activity data. No official patch or remediation level has been confirmed in the provided data.
Potential Impact
An attacker can cause a victim to be logged into an attacker-controlled account, leading to the victim's actions being recorded and accessible by the attacker. This compromises user session integrity and privacy but does not directly disclose confidential data or allow privilege escalation. The impact is rated high due to the potential for misuse of user sessions and data exposure.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider disabling the OAuth social login feature or applying any recommended temporary mitigations from the vendor. Monitor official Estatik plugin channels for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-20T08:37:22.844Z
- State
- PUBLISHED
Threat ID: 6a757731bf8831d539df5eb9
Added to database: 08/07/2026, 06:12:01 UTC
Last enriched: 08/14/2026, 15:56:54 UTC
Last updated: 09/21/2026, 22:01:32 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.