Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys
critical
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through san...
- CVSS:
- 9.8
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- Aug 21, 2026
CVE-2026-78003 on NVD →
Mailgun for WordPress <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary Mailgun List Subscription
medium
The Mailgun for WordPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 2.2.0. This is due to missing nonce verification and lack of server-side validation of submitted list addresses against configured lists in the add_list() function. This makes it possible for unauthenti...
- CVSS:
- 5.3
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- Jul 13, 2026
CVE-2026-14834 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database