Sendmachine for WordPress <= 1.0.20 - Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests
criticalThe Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated atta...
- CVSS:
- 9.8
- Affected:
- up to 1.0.20
- Fixed in:
- 2.0.0
- Disclosed:
- Apr 21, 2026