CVE-2026-78003 (matched: wordpress)

  • Sunday, 23rd August, 2026
  • 04:04am

A security flaw has been found in the Mailgun for WordPress plugin, affecting all versions up to and including 2.2.0. The issue is caused by the plugin not properly checking user-submitted data, which lets unauthenticated attackers send requests to Mailgun's services using your website's stored Mailgun API key, without needing to log in to your site first.

This vulnerability can be exploited to set up hidden email forwarding rules that intercept password reset emails sent to your site's administrator accounts. If an attacker gets access to these reset emails, they can take over your website's admin account and gain full control of your site's content

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003

« Back