WordPress Plugin Vulnerabilities
Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request Form
Description
The plugin does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
AUTHBYPASS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-30 (about 7 days ago)
Added
2026-07-30 (about 6 days ago)
Last Updated
2026-07-30 (about 6 days ago)