What is CVE-2026-18044?
The Estatik Real Estate plugin for WordPress (versions before 4.3.4) contains an email spoofing vulnerability due to a lack of validation on the recipient list used by its property request form. An unauthenticated attacker can exploit this to send emails to arbitrary recipients with arbitrary subject, body, and Reply-To header, potentially enabling phishing attacks. Users should update the plugin to version 4.3.4 or higher immediately.
Azərbaycanca: Estatik Real Estate plaginində (4.3.4 versiyasından əvvəl) kritik e-poçt saxtalığı zəifliyi aşkar edilib. Autentifikasiya olunmamış hücumçu, plaginin əmlak sorğu forması vasitəsilə göndərilən e-poçtların alıcı siyahısını yoxlamamasından istifadə edərək ixtiyari ünvana, ixtiyari mövzu, mətn və Reply-To ilə e-poçt göndərə bilər. Bu, fişinq hücumları üçün istifadə oluna bilər. Təsirə məruz qalan plagin istifadəçiləri dərhal 4.3.4 versiyasına yeniləməlidirlər.
FAQ2
How can the CVE-2026-18044 vulnerability in the Estatik Real Estate plugin be exploited?
An unauthenticated attacker can exploit the lack of validation on the recipient list used by the plugin's property request form to send emails to arbitrary recipients with arbitrary subject, body, and Reply-To header.
How can I protect against the CVE-2026-18044 vulnerability?
Affected plugin users should update the plugin to version 4.3.4 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.