
Attention WordPress users: CVE-2026-6963 affects WP Mail Gateway plugin versions up to 1.8, allowing attackers with Subscriber access to manipulate SMTP settings and escalate privileges. Update or patch promptly to protect your site. #cybersecurity
Post summary
The advisory warns about CVE‑2026‑6963 in WP Mail Gateway versions ≤1.8, enabling Subscriber‑role attackers to alter SMTP settings and elevate privileges; a patch is immediately recommended.


