A security vulnerability has been found in the Mailgun for WordPress plugin, impacting all versions of the tool up to and including 2.2.0. The flaw exists because the plugin does not properly validate user-provided input when processing address lists, allowing unauthenticated attackers to send forged, authorized requests to Mailgun's services using your WordPress site's stored Mailgun API key.
Attackers can exploit this access to set up hidden email forwarding rules that intercept password reset emails sent to your site's administrator accounts. If they obtain these reset emails, they can take over your website's admin account, giving them full control over your site, its content, and any data stored on it.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003