plugin

Mailgun Vulnerabilities

2 known security issues reported for the Mailgun WordPress plugin. Most recent disclosed Aug 21, 2026.

1 critical 1 medium

Running Mailgun on your site? Check whether your installed version is affected.

Scan your site free

Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys

critical

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through san...

CVSS:
9.8
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Aug 21, 2026

CVE-2026-78003 on NVD →

Mailgun for WordPress <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary Mailgun List Subscription

medium

The Mailgun for WordPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 2.2.0. This is due to missing nonce verification and lack of server-side validation of submitted list addresses against configured lists in the add_list() function. This makes it possible for unauthenti...

CVSS:
5.3
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Jul 13, 2026

CVE-2026-14834 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database