CVE-2026-76790
HIGH
NVD
CVSS Score
7.1
Severity
HIGH
Published
Sep 19, 2026
Vendor
unknown
Description
The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.