Arbitrary Email Sending Flaw in Estatik Real Estate Plugin for WordPress
CVE-2026-18044
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 August 2026
Badges
What is CVE-2026-18044?
The Estatik Real Estate Plugin for WordPress features a significant flaw where it fails to properly validate the recipient list intended for messages generated via its property request form. This oversight allows unauthenticated users to exploit the functionality and send emails to any arbitrary recipient, with the flexibility to manipulate the subject, body, and Reply-To headers. This poses a risk to sites where the form is configured to route messages to a custom address, potentially leading to phishing attacks or unauthorized information dissemination.
Affected Version(s)
Estatik Real Estate Plugin 0 < 4.3.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved