CVE-2026-78003 (matched: wordpress)

  • Monday, 24th August, 2026
  • 04:05am

A security vulnerability has been identified in the Mailgun for WordPress plugin, impacting all versions up to and including 2.2.0. This flaw lets outside attackers trick your WordPress site into sending unauthorized requests to Mailgun's services using your site's own stored Mailgun account credentials, without needing to log into your WordPress site first.

Attackers can exploit this flaw to set up hidden email forwarding rules through Mailgun that intercept password reset emails sent to your site's administrator accounts. If they succeed, they can take full control of your WordPress site's admin account, giving them access to all of your site's content, settings, and user data.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003

« Back