VYPR

ShopMonitor.io

by WordPress

CVEs (1)

  • CVE-2026-14919Jul 31, 2026
    risk 0.00cvss epss 0.00

    The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including…