CVE-2026-14547: Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request Form
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Estatik Real Estate Pluginto a version that resolves this vulnerability.Fixed in 4.3.3 - Compensating control
Restrict access to the WordPress site’s request/property form endpoint (e.g., via authentication/WAF/ACL) to limit unauthenticated use as a mail relay until the plugin is updated.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14547?
CVE-2026-14547 has a risk rating of 40, indicating a high severity level.
How do I fix CVE-2026-14547?
To fix CVE-2026-14547, update the Estatik Real Estate Plugin to version 4.3.3 or later.
What type of vulnerability is CVE-2026-14547?
CVE-2026-14547 is an unauthenticated arbitrary-recipient mail relay vulnerability.
Can unauthenticated users exploit CVE-2026-14547?
Yes, unauthenticated users can exploit CVE-2026-14547 to send emails to arbitrary recipients without any restrictions.
What impact does CVE-2026-14547 have on user data?
CVE-2026-14547 can lead to potential misuse of the site's email functionality, allowing unauthorized messages to be sent.