Impact
The Estatik Real Estate Plugin for WordPress versions before 4.3.4 fails to validate the recipient list it later uses for its property request form, letting anyone submit a form that is sent to any address with a chosen subject, body and Reply‑To field. This permits unauthenticated attackers to forge emails and potentially conduct phishing or spam campaigns, leveraging the site’s mail server. The weakness is a signed‑value mismatch (CWE‑345).
Affected Systems
WordPress sites running Estatik Real Estate Plugin version 4.3.3 or older. The vulnerability applies to any installation where the property request form is enabled and mails are routed to a custom address.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and no EPSS data is available, implying limited knowledge of exploitation frequency. The vulnerability is not listed in CISA’s KEV catalogue. The attack vector is unauthenticated web access to the form; an attacker need only submit the form with chosen email parameters. While the risk to confidentiality, integrity or availability is minimal, the potential for email spoofing and reputational damage is real, especially if the site’s mail server is used for marketing or user notifications.
OpenCVE Enrichment