CVE-2026-18044
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-18044 is an unauthenticated arbitrary-recipient mail relay vulnerability in the Estatik Real Estate Plugin for WordPress, caused by a signed-value mismatch in recipient list validation. The plugin fails to validate the recipient list it later uses to send messages via its property request form, enabling unauthenticated attackers to relay emails to arbitrary recipients with attacker-controlled subject, body, and Reply-To headers. All versions of the plugin before 4.3.4 are affected, and the vulnerability is only exploitable on sites where the form is configured to route to a custom address. It was publicly disclosed on August 6, 2026, and assigned a CVSS v3.1 base score of 3.7 (Low) (WPScan, GitHub Advisory).

Technical details

The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity): the plugin does not verify that the recipient list submitted via the property request form matches the intended, administrator-configured recipient before sending the email (GitHub Advisory). This signed-value mismatch allows an attacker to manipulate the recipient list in the form submission, effectively turning the plugin's mail-sending functionality into an open relay. Exploitation requires no authentication or user interaction, but does require the site to have the property request form configured to route to a custom address, raising the attack complexity to High (WPScan). The vulnerability was discovered and reported by Erwan LR of WPScan, with a proof-of-concept scheduled for public release on August 20, 2026.

Impact

Successful exploitation allows an unauthenticated attacker to send emails to arbitrary recipients using the affected WordPress site's mail infrastructure, with full control over the subject, body, and Reply-To headers. This enables phishing campaigns and email spoofing attacks that appear to originate from a legitimate domain, potentially damaging the site owner's reputation and email deliverability. There is no direct impact on confidentiality or availability; the integrity impact is rated Low and is limited to the email channel (WPScan, GitHub Advisory).

Exploitability

No public proof-of-concept exploit is currently available; WPScan has indicated the PoC will be published on August 20, 2026, to allow time for users to update (WPScan). There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the EPSS score is 0.0, indicating a very low probability of exploitation in the near term (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. NVD's SSVC assessment also classifies exploitation as "none" at this time.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Estatik Real Estate Plugin version below 4.3.4 that have the property request form configured to route to a custom email address (e.g., using Shodan, WPScan, or manual browsing).
  2. Locate the property request form: Navigate to a property listing page on the target site that exposes the contact/request form powered by the Estatik plugin.
  3. Craft a malicious form submission: Intercept the form submission (e.g., using Burp Suite) and manipulate the recipient list parameter to include arbitrary target email addresses, along with attacker-controlled values for the subject, body, and Reply-To fields.
  4. Submit the request: Send the crafted HTTP POST request to the form handler endpoint. Because the plugin does not validate the recipient list against the administrator-configured value, the email is dispatched to the attacker-specified recipients using the site's mail server.
  5. Achieve objective: The target recipients receive a spoofed email appearing to originate from the legitimate WordPress site, which can be used for phishing or social engineering (WPScan).

Indicators of compromise

  • Logs: WordPress mail logs or server SMTP logs showing outbound emails sent to unexpected or external recipients via the Estatik property request form handler; unusual volume of outbound emails from the web server.
  • Network: Outbound SMTP traffic to recipients not matching the administrator-configured custom address for the Estatik form.
  • Application Logs: HTTP POST requests to the Estatik property request form endpoint with anomalous or encoded recipient, subject, or body parameters in web server access logs.

Mitigation and workarounds

The vendor has released a patch in Estatik Real Estate Plugin version 4.3.4, which corrects the recipient list validation logic (WPScan, GitHub Advisory). Site administrators should update to version 4.3.4 or later immediately. If immediate patching is not feasible, a temporary workaround is to disable or restrict access to the property request form until the update can be applied.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18044NONEN/A
  • estatik
NoYesAug 12, 2026
CVE-2026-17008NONEN/A
  • quick-paypal-payments
NoNoAug 12, 2026
CVE-2026-16990NONEN/A
  • wp-paypal
NoNoAug 12, 2026
CVE-2026-16747NONEN/A
  • kirki
NoYesAug 12, 2026
CVE-2026-16621NONEN/A
  • woo-paypal-gateway
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management