CVE-2026-78003 (matched: wordpress)

  • Monday, 24th August, 2026
  • 22:04pm

A security vulnerability has been found in the Mailgun for WordPress plugin, affecting all versions up to and including 2.2.0. The issue occurs because the plugin does not properly validate user-submitted data, allowing unauthenticated attackers to send requests through your site’s Mailgun account using your site’s stored Mailgun API key, even without access to your WordPress login details.

Attackers can exploit this flaw to set up hidden email forwarding rules that capture password reset emails sent to your site’s administrators. If they obtain these reset links, they can take full control of admin accounts for your WordPress site.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003

« Back