PatchSiren

Estatik CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Estatik CVE published 2026-08-12

CVE-2026-18044

The Estatik Real Estate Plugin for WordPress has a vulnerability that allows unauthenticated users to send emails to arbitrary recipients with arbitrary subjects, bodies, and Reply-To information. This issue arises because the plugin does not validate the recipient list used in its property request form before sending the message. The vulnerability has a CVSS score of 3.7 and is classified as LOW severity.

HIGH Estatik CVE published 2026-08-07

CVE-2026-16262

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker. This vulnerability affects WordPress sites using the Estatik Real Estate Plugin, pa [truncated]

MEDIUM Estatik CVE published 2026-08-06

CVE-2026-14547

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing. This vulnerability affects WordPress sites using the Estati [truncated]