CVE-2026-78003 (matched: wordpress)

  • Sunday, 23rd August, 2026
  • 10:04am

A security vulnerability, tracked as CVE-2026-78003, has been found in the Mailgun for WordPress plugin, a tool used to connect WordPress websites to the Mailgun email service. All versions of the plugin up to and including 2.2.0 have a flaw caused by missing proper input checks in the code that manages address lists.

This flaw lets unauthenticated attackers send requests to Mailgun's systems using your website's stored Mailgun API key. Attackers could exploit this to set up hidden email forwarding rules that capture password reset emails sent to your site's administrators, which would allow them to take over administrator accounts on your WordPress site.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003

« Back