CVE-2026-78003 (matched: wordpress)

  • Sunday, 23rd August, 2026
  • 22:05pm

A security flaw has been found in the Mailgun for WordPress plugin, a common tool used to send and manage emails from WordPress websites, affecting all versions up to and including 2.2.0. The flaw exists because the plugin does not properly validate user input when processing address list requests. This allows unauthenticated attackers to send hidden, authorized requests to Mailgun's systems using your website's stored Mailgun API credentials, with no need to log into your WordPress admin area. Attackers could exploit this vulnerability to set up secret email forwarding rules that intercept password reset emails sent to your site's administrator accounts. If successful, this could let an attacker gain full administrative control of your WordPress website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003

« Back