External risk intelligence

Estatik Subscriber Privilege Escalation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-96350

Estatik is a WordPress plugin used for real estate listings. As a plugin designed for public-facing websites to display property information, it is typically deployed in environments accessible via the public internet.

Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability identified in the Estatik plugin, which is used for real estate listings. The issue allows for subscriber privilege escalation, meaning unauthorized users could potentially gain higher-level access within systems utilizing this plugin. The primary concern is to determine if your organization uses this specific plugin and is therefore potentially exposed.

  • Unauthorized users could gain higher system access.
  • Key issue is determining if your organization is affected.
  • Confirm relevance to understand potential business exposure.

Attack Path

How an attacker could exploit the issue

This vulnerability allows any unauthenticated attacker to gain administrative privileges on a website using the Estatik plugin. The attacker can exploit this by sending specially crafted requests to the vulnerable plugin. Once successful, an attacker could take full control of the website.

  • Requires no user interaction.
  • Exploited via network requests.
  • Leads to full administrative control.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to gain administrative access to an Estatik-powered website, potentially leading to unauthorized modifications of real estate listings and site content. This exposure is possible when the plugin is installed and the system is accessible via the network.

  • Real estate listing data and site content.
  • Unauthenticated network access to the plugin.
  • Complete site takeover and content alteration.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Estatik plugin's privilege escalation vulnerability, accessible via the network, likely impacts public-facing WordPress sites and requires coordinated action. Application owners, in conjunction with infrastructure and security teams, should prioritize identifying all instances of Estatik, assessing their exposure and business criticality, and confirming ownership before planning remediation. Vendor coordination will be key for addressing the underlying issue.

  • App owners and security teams should investigate.
  • Verify Estatik plugin presence and reachability.
  • Plan coordinated remediation and vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Estatik plugin?

Estatik is a software plugin for WordPress designed to help real estate professionals manage and display property listings online. It provides the necessary framework for websites to showcase homes, filter search results, and handle listing data, making it a common tool for public-facing real estate portals.

What does CWE-266 mean for CVE-2026-96350?

CWE-266 refers to Incorrect Privilege Assignment. In this context, it means the plugin fails to properly verify or restrict a user's rights, allowing someone with low-level subscriber access to obtain higher-level permissions, such as those reserved for site administrators.

How can an attacker trigger this privilege escalation?

An attacker triggers the vulnerability by sending specially crafted network requests to the plugin. Because the issue involves privilege escalation rather than a lack of authentication, simply visiting the site or performing standard browsing actions does not trigger the bug; it requires intentional, malformed requests directed at the plugin's functionality.

Why should I care about this if my site is on the internet?

According to Halo Surface Signal, Estatik is typically deployed on public-facing websites to display property information, making it inherently accessible via the internet. Because the vulnerability allows for unauthorized administrative access, any site reachable by the public is at significant risk of being fully compromised by remote actors.

How do I respond if I am running Estatik?

Begin by confirming whether your organization uses the Estatik plugin and verify its version. Since this is a critical issue, coordinate with your technical team to identify all active instances, determine the business impact, and engage with the vendor for official security updates or guidance to secure your environment.

References