CVE-2026-78003 (matched: wordpress)

  • Monday, 24th August, 2026
  • 16:03pm

A security vulnerability has been identified in the Mailgun for WordPress plugin, affecting all versions up to and including 2.2.0. This flaw allows unauthenticated attackers to send requests to Mailgun's services using your WordPress site's stored Mailgun API key, without needing access to your site or Mailgun account.

The most serious risk from this issue is that attackers can create hidden inbound email forwarding rules via Mailgun, which redirect all incoming emails to an address they control. This includes password reset emails for your site's administrator account, which would let the attacker take over your admin account and gain full control over your WordPress website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003

« Back