Impact
The Estatik Real Estate Plugin before version 4.3.3 does not enforce its anti‑spam mechanism and allows any visitor to specify arbitrary email recipients, subjects, bodies and reply‑to addresses. The result is that the WordPress site can be abused as an outbound mail relay, facilitating large‑scale spam or phishing campaigns. This does not grant direct code execution or data exfiltration, but it compromises the server’s reputation and may lead to its IP being blacklisted, thereby impacting email deliverability for legitimate communications.
Affected Systems
Any WordPress installation that has the Estatik Real Estate Plugin installed and running a revision older than 4.3.3 is affected. No other vendors or products are currently enumerated.
Risk and Exploitability
The vulnerability is exploitable by unauthenticated users over the public network via normal HTTP requests to the plugin’s request form. The CVSS score is not provided; however the nature of the flaw—unauthenticated privilege escalation to send arbitrary mail—indicates a moderate to high severity. The EPSS score is not available, but the lack of authentication prerequisites and the potential for large‑scale abuse suggest a high likelihood of exploitation. This issue is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment