CRITICAL 9.8 CVE-2026-78003 Published 22 Aug 2026

Mailgun WordPress Plugin SSRF Vulnerability

Worried this affects one of your servers?

The Mailgun for WordPress plugin is affected. It's vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0.

An unauthenticated attacker can exploit this to make authenticated POST requests to any Mailgun API endpoint using the WordPress site's API key. This includes creating inbound email-forwarding routes that can intercept password reset emails, leading to administrator account takeover.

Reference: CVE-2026-78003 on NVD

← Back to Security News