PatchSiren cyber security CVE debrief
CVE-2026-14547 Estatik CVE debrief
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing. This vulnerability affects WordPress sites using the Estatik Real Estate Plugin, particularly those concerned with preventing spam and phishing attacks. The plugin's insufficient anti-spam checks and unrestricted recipient routing enable attackers to send emails with arbitrary subjects, bodies, and Reply-To headers. To mitigate this vulnerability, defenders should verify the plugin version, restrict recipient routing of the property request form, and implement additional anti-spam checks. Evidence from WPScan and official CVE and NVD records supports this assessment.
- Vendor
- Estatik
- Product
- Estatik Real Estate Plugin
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Administrators of WordPress sites using the Estatik Real Estate Plugin, especially those concerned with preventing spam and phishing attacks, should verify the plugin version and implement additional anti-spam checks. They should also monitor for suspicious email activity and restrict recipient routing of the property request form. This vulnerability may impact operators who rely on the plugin for property management and security teams responsible for monitoring and mitigating potential threats.
Technical summary
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 is vulnerable to unauthorized email relay due to insufficient anti-spam checks and unrestricted recipient routing in its property request form. This allows unauthenticated users to send emails to arbitrary recipients with arbitrary subjects, bodies, and Reply-To headers, effectively turning the site into a mail relay for spam or phishing attacks.
Defensive priority
Medium priority due to potential for spam or phishing attacks
Recommended defensive actions
- Verify the Estatik Real Estate Plugin WordPress plugin version and upgrade to 4.3.3 or later
- Restrict recipient routing of the property request form
- Implement additional anti-spam checks
- Monitor for suspicious email activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from WPScan indicates a vulnerability in the Estatik Real Estate Plugin WordPress plugin before 4.3.3. Official CVE and NVD records provide additional context. The vulnerability allows unauthenticated users to send emails to arbitrary recipients with arbitrary subjects, bodies, and Reply-To headers. Defenders should verify the plugin version and restrict recipient routing of the property request form. Evidence limits suggest focusing on CVE and NVD records for further details.
Official resources
-
CVE-2026-14547 CVE record
CVE.org
-
CVE-2026-14547 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:27.870Z and has not been modified since then.