
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18044 is an unauthenticated arbitrary-recipient mail relay vulnerability in the Estatik Real Estate Plugin for WordPress, caused by a signed-value mismatch in recipient list validation. The plugin fails to validate the recipient list it later uses to send messages via its property request form, enabling unauthenticated attackers to relay emails to arbitrary recipients with attacker-controlled subject, body, and Reply-To headers. All versions of the plugin before 4.3.4 are affected, and the vulnerability is only exploitable on sites where the form is configured to route to a custom address. It was publicly disclosed on August 6, 2026, and assigned a CVSS v3.1 base score of 3.7 (Low) (WPScan, GitHub Advisory).
The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity): the plugin does not verify that the recipient list submitted via the property request form matches the intended, administrator-configured recipient before sending the email (GitHub Advisory). This signed-value mismatch allows an attacker to manipulate the recipient list in the form submission, effectively turning the plugin's mail-sending functionality into an open relay. Exploitation requires no authentication or user interaction, but does require the site to have the property request form configured to route to a custom address, raising the attack complexity to High (WPScan). The vulnerability was discovered and reported by Erwan LR of WPScan, with a proof-of-concept scheduled for public release on August 20, 2026.
Successful exploitation allows an unauthenticated attacker to send emails to arbitrary recipients using the affected WordPress site's mail infrastructure, with full control over the subject, body, and Reply-To headers. This enables phishing campaigns and email spoofing attacks that appear to originate from a legitimate domain, potentially damaging the site owner's reputation and email deliverability. There is no direct impact on confidentiality or availability; the integrity impact is rated Low and is limited to the email channel (WPScan, GitHub Advisory).
No public proof-of-concept exploit is currently available; WPScan has indicated the PoC will be published on August 20, 2026, to allow time for users to update (WPScan). There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the EPSS score is 0.0, indicating a very low probability of exploitation in the near term (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. NVD's SSVC assessment also classifies exploitation as "none" at this time.
The vendor has released a patch in Estatik Real Estate Plugin version 4.3.4, which corrects the recipient list validation logic (WPScan, GitHub Advisory). Site administrators should update to version 4.3.4 or later immediately. If immediate patching is not feasible, a temporary workaround is to disable or restrict access to the property request form until the update can be applied.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."