CVE-2026-78003 (matched: wordpress)

  • Saturday, 22nd August, 2026
  • 10:05am

A security vulnerability identified as CVE-2026-78003 impacts the Mailgun for WordPress plugin, affecting all versions up to and including 2.2.0. The flaw occurs because the plugin does not properly check user-provided input when handling address lists, letting unauthenticated attackers send requests using your site's private Mailgun API key without accessing your WordPress dashboard.

Attackers can exploit this access to create hidden email forwarding rules via Mailgun, which will capture password reset emails sent to your site's administrator accounts. This creates a risk of bad actors taking full control of your WordPress site's administrator accounts.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003

« Back