CVSS
5.3
CVSS v3.1
EPSS
0.2%
Exploit Prediction Score
Published
August 6, 2026
Exploitability
EPSS probability 0.2%
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).