PT-2026-68394 · WordPress · Estatik Real Estate Plugin
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Estatik Real Estate Plugin versions prior to 4.3.3
Description
This issue occurs because the property request form does not properly enforce anti-spam checks or restrict recipient routing. This allows unauthenticated users to send emails to arbitrary recipients with custom subjects, bodies, and
Reply-To headers, enabling the site to be used as a mail relay for spam or phishing campaigns.Recommendations
Update Estatik Real Estate Plugin to version 4.3.3 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Estatik Real Estate Plugin