Description
The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is configured to route to a custom address.
Published: 2026-08-12
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Estatik Real Estate Plugin for WordPress versions before 4.3.4 fails to validate the recipient list it later uses for its property request form, letting anyone submit a form that is sent to any address with a chosen subject, body and Reply‑To field. This permits unauthenticated attackers to forge emails and potentially conduct phishing or spam campaigns, leveraging the site’s mail server. The weakness is a signed‑value mismatch (CWE‑345).

Affected Systems

WordPress sites running Estatik Real Estate Plugin version 4.3.3 or older. The vulnerability applies to any installation where the property request form is enabled and mails are routed to a custom address.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity, and no EPSS data is available, implying limited knowledge of exploitation frequency. The vulnerability is not listed in CISA’s KEV catalogue. The attack vector is unauthenticated web access to the form; an attacker need only submit the form with chosen email parameters. While the risk to confidentiality, integrity or availability is minimal, the potential for email spoofing and reputational damage is real, especially if the site’s mail server is used for marketing or user notifications.

Generated by OpenCVE AI on August 13, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Estatik Real Estate Plugin to version 4.3.4 or later so the recipient list is validated properly.
  • If an upgrade is not immediately possible, temporarily disable or remove the property request form, or restrict access to its URL so only authenticated users can submit it.
  • Configure the WordPress mail settings or employ a mail filtering plugin to prevent the site from sending emails to arbitrary external addresses, limiting spoofing risk.

Generated by OpenCVE AI on August 13, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is configured to route to a custom address.
Title Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T12:08:41.797Z

Reserved: 2026-07-28T09:38:37.599Z

Link: CVE-2026-18044

cve-icon Vulnrichment

Updated: 2026-08-12T12:08:36.436Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T12:17:47.443

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-18044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:30:05Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity