1 vulnerability across 1 product scored HIGH or above on August 22, 2026.

  • ๐ŸŸ  HIGH: 1

๐ŸŸ  [HIGH] mailgun/mailgun_for_wordpress

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:mailgun:mailgun_for_wordpress:*:*:*:*:*:*:*:*

Mailgun for WordPress โ€” Critical SSRF via Path Traversal

The Mailgun for WordPress plugin versions up to and including 2.2.0 is affected by one critical-severity vulnerability (CVSS 9.8). CVE-2026-78003 is a Server-Side Request Forgery flaw in the add_list() function, where insufficient input validation on user-controlled array keys allows unauthenticated attackers to craft requests that reach arbitrary Mailgun API endpoints using the site’s own API key. This effectively lets an external attacker hijack the site’s Mailgun integration to send emails, modify mailing lists, or exfiltrate account data without any authentication.

WordPress administrators using this plugin should update immediately once a patched version is available and review Mailgun API logs for any unauthorized activity. If no patch is yet released, consider deactivating the plugin and rotating your Mailgun API key as an interim mitigation. Teams managing WordPress environments at scale should prioritize this due to the unauthenticated attack vector and the high potential for abuse of email infrastructure.

Vendor Advisory