A security flaw tracked as CVE-2026-78003 has been found in the Mailgun for WordPress plugin, affecting all versions up to and including 2.2.0. The issue exists because the plugin does not properly validate user-submitted data when processing address lists, creating an opening for attackers.
Unauthenticated attackers can exploit this gap to send unauthorized requests using your site's connected Mailgun API key. If successful, they could set up hidden email forwarding rules through your Mailgun account that intercept password reset emails sent to your site's administrators, potentially allowing them to take full control of your site's admin accounts.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78003