CVE-2026-78003
No known patch is available for this vulnerability.
The affected plugin has not been updated on WordPress.org since before this CVE was disclosed; the latest installable version is still vulnerable. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
Description
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through sanitize_text_field(). This makes it possible for unauthenticated attackers to make authenticated POST requests to any Mailgun API endpoint using the WordPress site's API key, including creating inbound email-forwarding routes that can intercept password reset emails, leading to administrator account takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.2.0
Patches
Vulnerability mechanics
References
9- plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.phpnvd
- plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.phpnvd
- plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.phpnvd
- plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.phpnvd
- plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.phpnvd
- plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.phpnvd
- plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.phpnvd
- plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.phpnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/110e888d-69fc-4682-b908-2b62288c5227nvd
News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)Wordfence Blog · Aug 27, 2026
- WordPress Plugins: 25 Vulnerabilities Disclosed, Including Critical Auth Bypass and Code Execution FlawsVypr Intelligence · Aug 23, 2026