CVE-2026-18044
Received Received - Intake

Unauthenticated Email Injection in Estatik Real Estate Plugin

Vulnerability report for CVE-2026-18044, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: WPScan

Description

The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is configured to route to a custom address.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
estatik real_estate_plugin to 4.3.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Estatik Real Estate Plugin for WordPress before version 4.3.4 has a flaw where it does not validate the recipient list in its property request form. This allows unauthenticated users to send emails to any address with custom subject, body, and Reply-To fields.

Detection Guidance

Check the installed version of the Estatik Real Estate Plugin in WordPress. If it is below 4.3.4, the system is vulnerable. Inspect the property request form for email routing to custom addresses and verify if recipient fields can be manipulated.

Impact Analysis

Attackers could exploit this to send spam or phishing emails from your website, potentially damaging your reputation or tricking users. It may also lead to your server being blacklisted if used for malicious purposes.

Compliance Impact

This vulnerability could lead to unauthorized email transmissions, potentially violating data protection laws like GDPR or HIPAA if sensitive data is involved. Organizations may face compliance penalties if exploited.

Mitigation Strategies

Update the Estatik Real Estate Plugin to version 4.3.4 or later immediately. Disable the property request form if not in use or restrict access to authenticated users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18044. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart