What is CVE-2026-16262?
A vulnerability in the Estatik Real Estate Plugin for WordPress (before version 4.3.3) fails to bind its OAuth social login flow to the initiating user session. This allows an unauthenticated attacker to perform a login CSRF attack, logging a victim into an attacker-controlled account, where the victim's subsequent activity is stored.
Azərbaycanca: Estatik Real Estate Plugin üçün CVE-2026-16262 zəifliyi aşkarlanıb. Plugin 4.3.3 versiyasından əvvəl OAuth sosial giriş zamanı istifadəçi sessiyasını düzgün yoxlamır, bu da autentifikasiya olunmamış hücumçuya qurbanı idarə etdiyi hesaba daxil etməyə imkan verir (login CSRF). İstifadəçilərə plugin-i ən azı 4.3.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
How to protect against CVE-2026-16262?
Users are advised to update the Estatik Real Estate Plugin to at least version 4.3.3.
What type of attack is CVE-2026-16262?
This vulnerability relates to a login CSRF attack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.