CVE-2026-78003 (matched: wordpress)

  • Monday, 24th August, 2026
  • 10:05am

If you operate a WordPress site with the Mailgun for WordPress plugin installed, be aware that versions 2.2.0 and older contain a security vulnerability. This flaw allows people who do not have access to your WordPress admin login to send requests using your site’s private Mailgun API key, without your knowledge.

Attackers could exploit this to create email forwarding rules via your Mailgun account, which would intercept password reset emails sent to your site’s administrators. If they obtain these reset links, they can take over admin accounts on your WordPress site, giving them full control over your site’s backend and content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003

« Back