← back
CVE-2026-18044lowCWE-345

Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 3.7epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is configured to route to a custom address.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.