CVE-2026-14547
Received Received - Intake

Email Relay Vulnerability in Estatik Real Estate Plugin

Vulnerability report for CVE-2026-14547, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-16
AI Q&A
2026-08-06
EPSS Evaluated
2026-08-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
estatik real_estate_plugin to 4.3.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Estatik Real Estate Plugin for WordPress before version 4.3.3 has a flaw where it does not properly enforce anti-spam checks or restrict recipient routing in its property request form. This allows unauthenticated users to send emails to any recipient with customizable subject, body, and Reply-To fields, effectively using the website as a mail relay for spam or phishing campaigns.

Detection Guidance

To detect this vulnerability, check if your WordPress site is running the Estatik Real Estate Plugin version before 4.3.3. You can use the WordPress admin panel to view the plugin version or run the command 'wp plugin list' in the WordPress root directory if using WP-CLI. Additionally, monitor outgoing email logs for unusual activity such as emails sent to arbitrary recipients via the property request form.

Impact Analysis

This vulnerability can allow attackers to send spam or phishing emails through your website without authentication. It may lead to your site being blacklisted by email providers, damage your reputation, and consume server resources. Additionally, it could be used to trick recipients into disclosing sensitive information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR if personal data is mishandled through phishing emails sent via the site. For HIPAA, if the plugin is used in a healthcare context, unauthorized email relaying could expose protected health information, violating confidentiality requirements.

Mitigation Strategies

Immediately update the Estatik Real Estate Plugin to version 4.3.3 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Review and restrict outgoing email functionality on the server to prevent abuse. Monitor email logs for suspicious activity during this period.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14547. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart