The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
El complemento de WordPress Estatik Real Estate Plugin anterior a 4.1.1 no sanitiza ni escapa varios parĂ¡metros y URL generadas antes de devolverlos en atributos, lo que genera cross site scripting reflejado que podrĂa usarse contra usuarios con privilegios elevados, como administradores.
The Estatik Real Estate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add/remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.