CVE-2026-14547: CWE-287 Improper Authentication in Estatik Real Estate Plugin
The Estatik Real Estate Plugin for WordPress before version 4.3.3 contains an authentication flaw that allows unauthenticated users to send emails through the site's property request form without proper anti-spam checks or recipient restrictions. This enables attackers to use the site as a mail relay to send emails with arbitrary recipients, subjects, bodies, and Reply-To headers, potentially facilitating spam or phishing campaigns.
AI Analysis
Technical Summary
CVE-2026-14547 describes an improper authentication vulnerability (CWE-287) in the Estatik Real Estate Plugin for WordPress versions prior to 4.3.3. The plugin fails to enforce its anti-spam mechanisms and does not restrict recipient routing in its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary content. This effectively turns the affected site into an open mail relay, which can be abused for spam or phishing attacks. The vulnerability has a CVSS 3.1 base score of 5.3 (medium severity) with network attack vector, low attack complexity, no privileges required, no user interaction, and impacts integrity but not confidentiality or availability.
Potential Impact
The vulnerability allows unauthenticated attackers to send arbitrary emails from the affected WordPress site, potentially enabling spam or phishing campaigns that appear to originate from a legitimate domain. This can damage the reputation of the site owner and may lead to blacklisting of the domain or IP address. There is no direct impact on confidentiality or availability of the site itself.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider disabling or restricting the property request form functionality or implementing additional email sending restrictions to prevent abuse. Monitor for updates from the plugin vendor regarding a security patch or official mitigation.
CVE-2026-14547: CWE-287 Improper Authentication in Estatik Real Estate Plugin
Description
The Estatik Real Estate Plugin for WordPress before version 4.3.3 contains an authentication flaw that allows unauthenticated users to send emails through the site's property request form without proper anti-spam checks or recipient restrictions. This enables attackers to use the site as a mail relay to send emails with arbitrary recipients, subjects, bodies, and Reply-To headers, potentially facilitating spam or phishing campaigns.
CVSS v3.1
Score 5.3medium
Affected software
Estatik Real Estate Plugin
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-14547 describes an improper authentication vulnerability (CWE-287) in the Estatik Real Estate Plugin for WordPress versions prior to 4.3.3. The plugin fails to enforce its anti-spam mechanisms and does not restrict recipient routing in its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary content. This effectively turns the affected site into an open mail relay, which can be abused for spam or phishing attacks. The vulnerability has a CVSS 3.1 base score of 5.3 (medium severity) with network attack vector, low attack complexity, no privileges required, no user interaction, and impacts integrity but not confidentiality or availability.
Potential Impact
The vulnerability allows unauthenticated attackers to send arbitrary emails from the affected WordPress site, potentially enabling spam or phishing campaigns that appear to originate from a legitimate domain. This can damage the reputation of the site owner and may lead to blacklisting of the domain or IP address. There is no direct impact on confidentiality or availability of the site itself.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider disabling or restricting the property request form functionality or implementing additional email sending restrictions to prevent abuse. Monitor for updates from the plugin vendor regarding a security patch or official mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-03T08:32:47.232Z
- State
- PUBLISHED
Threat ID: 6a742933bf8831d53945d72d
Added to database: 08/06/2026, 06:26:59 UTC
Last enriched: 08/13/2026, 17:27:21 UTC
Last updated: 09/21/2026, 22:01:32 UTC
Views: 31
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.