CVE-2026-18044: Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch
The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is configured to route to a custom address.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/estatik-real-estate-pluginto a version that resolves this vulnerability.Fixed in 4.3.4 - Compensating control
If possible, restrict access to the Estatik property request form endpoint (where the form routes to a custom address) so unauthenticated users cannot submit requests that trigger arbitrary-recipient mail relay.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18044?
The severity of CVE-2026-18044 is classified as low with a score of 3.7.
How do I fix CVE-2026-18044?
To fix CVE-2026-18044, update the Estatik Real Estate Plugin to version 4.3.4 or later.
What type of vulnerability is CVE-2026-18044?
CVE-2026-18044 is an unauthenticated arbitrary-recipient mail relay vulnerability.
What are the implications of CVE-2026-18044?
CVE-2026-18044 allows unauthenticated users to send emails to arbitrary recipients with custom content.
Which software is affected by CVE-2026-18044?
The affected software is the Estatik Real Estate Plugin for WordPress versions prior to 4.3.4.