CVE-2026-78003Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through sanitize_text_field(). This makes it possible for unauthenticated attackers to make authenticated POST requests to any Mailgun API endpoint using the WordPress site's API key, including creating inbound email-forwarding routes that can intercept password reset emails, leading to administrator account takeover.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-22); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-22: 3Mentions · 2026-08-24: 1Patch / Workaround · 2026-08-22: 1Technical Details · 2026-08-22: 308-2208-24
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-223
Disclosure2Patch1
2026-08-241
General1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78003 Mailgun for WordPress SSRF via Path Traversal Enables Account Takeover https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78003

    Post summary

    A newly disclosed CVE (CVE‑2026‑78003) identifies an SSRF via path traversal flaw in Mailgun for WordPress that can lead to account takeover, with no active exploitation, PoC, or patch information reported.

    00011154
    4.1K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en Complemento de WordPress ❗ CVE-2026-78003 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-complemento-de-wordpress-10/ https://t.co/vJstqkooyh

    Post summary

    The tweet simply announces the existence of a WordPress plugin vulnerability (CVE‑2026‑78003) and points to additional information via a link.

    00000216
    6.7K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-78003 (CVSS 9.8) affects Mailgun for WordPress plugin <=2.2.0 via SSRF. Update the plugin if in use. https://nvd.nist.gov/vuln/detail/CVE-2026-78003 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/CZdRQRXaYI

    Post summary

    The tweet reports a high‑CVSS SSRF vulnerability (CVE‑2026‑78003) in Mailgun for WordPress plugin and urges users to update the plugin to mitigate the risk.

    0000036
    93 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-78003 The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is d… https://www.cve.org/CVERecord?id=CVE-2026-78003

    Post summary

    The CVE‑2026‑78003 vulnerability discloses an SSRF flaw in the Mailgun for WordPress plugin affecting versions up to 2.2.0, with no PoC, exploit code, or active attack evidence mentioned.

    000001.0K
    58.0K followersView on X

Explore more