PT-2026-68394 · WordPress · Estatik Real Estate Plugin

·

CVE-2026-14547

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Estatik Real Estate Plugin versions prior to 4.3.3
Description This issue occurs because the property request form does not properly enforce anti-spam checks or restrict recipient routing. This allows unauthenticated users to send emails to arbitrary recipients with custom subjects, bodies, and Reply-To headers, enabling the site to be used as a mail relay for spam or phishing campaigns.
Recommendations Update Estatik Real Estate Plugin to version 4.3.3 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14547

Affected Products

Estatik Real Estate Plugin