Impact
The Estatik Real Estate Plugin before version 4.3.3 does not enforce its anti‑spam mechanism and allows any visitor to specify arbitrary email recipients, subjects, bodies and reply‑to addresses. The result is that the WordPress site can be abused as an outbound mail relay, facilitating large‑scale spam or phishing campaigns. This does not grant direct code execution or data exfiltration, but it compromises the server’s reputation and may lead to its IP being blacklisted, thereby impacting email deliverability for legitimate communications. The vulnerability is caused by weaknesses such as lack of adequate authorization checks (CWE‑285), missing authentication (CWE‑287), and improper recipient routing validation (CWE‑863).
Affected Systems
Any WordPress installation that has the Estatik Real Estate Plugin installed and running a revision older than 4.3.3 is affected. No other vendors or products are currently enumerated.
Risk and Exploitability
The vulnerability is exploitable by unauthenticated users over the public network via normal HTTP requests to the plugin’s request form. The CVSS score is 5.3, indicating moderate severity. The EPSS score is < 1%, suggesting a low probability of exploitation. This issue is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment