Unrated severityNVD Advisory· Published Aug 6, 2026
Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request Form
CVE-2026-14547
Description
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing.
Affected products
1- Range: <4.3.3
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/5c208be8-57db-4f74-8030-398c1eece293/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.