A security flaw has been found in the Mailgun for WordPress plugin, a tool used to link WordPress websites to the Mailgun email service. The vulnerability affects all versions of the plugin up to and including version 2.2.0.
Unauthenticated attackers can exploit this issue to send requests using your website’s private Mailgun API key. This could let them create hidden email forwarding rules that intercept password reset emails intended for your site’s administrators, potentially giving them full control of your WordPress admin account.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003