VYPR

Mailgun for WordPress

by WordPress

CVEs (2)

  • CVE-2026-78003CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from…

  • CVE-2026-14834MedJul 31, 2026
    risk 0.42cvss 6.5epss 0.00

    The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses…