The Estatik Real Estate Plugin for WordPress has a vulnerability that allows unauthenticated users to send emails to arbitrary recipients with arbitrary subjects, bodies, and Reply-To information. This issue arises because the plugin does not validate the recipient list used in its property request form before sending the message. The vulnerability has a CVSS score of 3.7 and is classified as LOW severity.
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker. This vulnerability affects WordPress sites using the Estatik Real Estate Plugin, pa [truncated]
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing. This vulnerability affects WordPress sites using the Estati [truncated]