What is CVE-2026-14547?
The Estatik Real Estate Plugin for WordPress before version 4.3.3 does not properly enforce its anti-spam check, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body, and Reply-To via the property request form. Update the plugin to version 4.3.3 immediately.
Azərbaycanca: WordPress üçün Estatik Real Estate pluginində (4.3.3-dən əvvəl) anti-spam yoxlaması düzgün tətbiq olunmur. Bu, autentifikasiyasız istifadəçilərə əmlak sorğu forması vasitəsilə istənilən ünvana, istədikləri mövzu, mətn və Reply-To ilə e-poçt göndərməyə imkan verir. Plugin dərhal 4.3.3 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What can an attacker do by exploiting CVE-2026-14547?
Unauthenticated users can send emails to arbitrary recipients with an arbitrary subject, body, and Reply-To via the property request form.
How can I fix the CVE-2026-14547 vulnerability?
Update the Estatik Real Estate Plugin for WordPress to version 4.3.3 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.