CVE-2026-78003 (matched: wordpress)

  • Sunday, 23rd August, 2026
  • 16:09pm

A security vulnerability has been found in the Mailgun for WordPress plugin, impacting all versions up to and including 2.2.0. The flaw is a server-side request forgery (SSRF) issue caused by insufficient input validation when the plugin processes address data submitted via forms on your WordPress site.

Unauthenticated attackers can exploit this gap to send authorized requests to Mailgun’s API using your site’s stored Mailgun API key. A high-risk possible outcome of this attack is the creation of hidden email forwarding rules that intercept password reset emails sent to your site’s administrators, which could allow an attacker to take over an administrator account for your WordPress site.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003

« Back