Product
estatik
8 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-48136
CVE-2023-6050
CVE-2023-6049
CVE-2023-6048
CVE-2023-28490
CVE-2023-40601
CVE-2016-10959
CVE-2016-10958
<= 2.0.12
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik M
< 4.1.1
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs be
< 4.1.1
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow un
< 4.1.1
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribe
<= 2.0.7
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Mortgage Calculator plugin <= 2.0.7 versions.
<= 2.0.7
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Mortgage Calculator plugin <= 2.0.7 versions.
< 2.3.1
The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[
< 2.3.0
The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-aj