AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14547

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Estatik Real Estate Plugin for WordPress versions prior to 4.3.3 is vulnerable due to inadequate enforcement of anti-spam checks and improper recipient routing in its property request form. This flaw allows unauthenticated users to exploit the plugin to send emails to arbitrary recipients, potentially facilitating spam or phishing attacks. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of abuse.

CVE
CVE-2026-14547
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing.