CVE-2026-6235Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the plugin's SMTP configuration, which can be leveraged to intercept all outbound emails from the site (including password reset emails).

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-22); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-04-22: 3Mentions · 2026-04-23: 2Mentions · 2026-04-25: 1Mentions · 2026-05-01: 1PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-25: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-22: 3Technical Details · 2026-04-23: 2Technical Details · 2026-05-01: 104-2204-2304-2505-01
Signal classification4 categories
Disclosure
342.9%
General
228.6%
Patch
114.3%
PoC
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-223
Disclosure2Patch1
2026-04-232
Disclosure1General1
2026-04-251
PoC1
2026-05-011
General1
Full discourse7 posts
  • DFIR Radar@DFIR_Radar
    General

    Weekly WordPress security report: 157 vulnerabilities across 122 plugins and 27 themes, including 6 critical-rated flaws. CVE-2026-3844 (Breeze Cache) and CVE-2026-6235 (Sendmachine) enable unauthenticated RCE. #DFIR_Radar https://t.co/szjCzDq5w4

    Post summary

    The tweet lists two CVEs with brief technical details about unauthenticated remote code execution in WordPress plugins, but provides no PoC, exploit code, active exploitation claims, or patch information. Overall, it is a simple announcement of vulnerability findings.

    10010107
    1.7K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6235 — CVSS 9.8/10 ██████████ The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/dfcIY9iuJl

    Post summary

    The tweet alerts to a critical authorization bypass in the Sendmachine WordPress plugin (CVE‑2026‑6235) and urges users to apply the available patch.

    1000056
    28 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6235-sendmachine-version-1-0-20-critical-vulnerability-proof-of-concept CVE-2026-6235 #WordPress plugin #vulnerability sendmachine #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    This post announces a proof‑of‑concept for CVE-2026-6235 on the SendMachine WordPress plugin, but offers no technical exploitation details or active usage indicators.

    0000052
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6235 The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, … https://www.cve.org/CVERecord?id=CVE-2026-6235

    Post summary

    The text announces the discovery of an authorization bypass vulnerability in the Sendmachine for WordPress plugin and provides technical details, but no PoC, exploit, patch, or exploitation evidence.

    00000118
    57.2K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-41679 | CVSS 10.0 🔴 CVE-2026-41228 | CVSS 9.9 🔴 CVE-2026-6235 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    This post lists three newly disclosed CVEs with high CVSS scores and points to an external link for further details, but does not provide evidence of PoC, exploit, active use, patches, or debunking.

    0000095
    5.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6235 Authorization Bypass in Sendmachine for WordPress Plugin Versions Up to 1.0.20 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6235

    Post summary

    The text announces a newly identified authorization bypass vulnerability in the Sendmachine WordPress plugin (up to version 1.0.20), presenting basic technical details but no PoC, exploit, or remediation information.

    0000055
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-6235: Sendmachine for WordPress <= 1.0.... Unauthenticated SMTP hijack = game over for any WordPress site using password resets - attackers own your entire user ba... https://zerodaysignal.com/vulnerability/CVE-2026-6235 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The message announces CVE-2026-6235, highlighting an unauthenticated SMTP hijack risk in Sendmachine for WordPress, but offers no PoC, exploit code, remediation, or evidence of active exploitation.

    0000095
    218 followersView on X

Explore more