{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mailgun-for-wordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-78003"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mailgun for WordPress"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Mailgun for WordPress plugin is susceptible to a high-severity Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-78003, affecting all versions up to and including 2.2.0. The vulnerability stems from insufficient input validation within the add_list() function. Specifically, the plugin processes user-controlled input from the $_POST['addresses'] parameter using only sanitize_text_field(), which fails to adequately block malicious input.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can leverage this flaw to send arbitrary POST requests to external Mailgun API endpoints. Because the plugin relies on the site's locally stored API key to authenticate these requests, the attacker can manipulate Mailgun routing configurations. A critical impact of this vulnerability is the ability to create unauthorized inbound email-forwarding routes, which can be configured to intercept password reset tokens, ultimately allowing an attacker to hijack administrator accounts. This flaw highlights the risks associated with improper handling of user-supplied data in administrative plugin functions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a target WordPress site running a vulnerable version (\u0026lt;= 2.2.0) of the Mailgun for WordPress plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP POST request targeting the endpoint handling the add_list() functionality.\u003c/li\u003e\n\u003cli\u003eThe attacker injects malicious payload data into the $_POST['addresses'] parameter to bypass input sanitization.\u003c/li\u003e\n\u003cli\u003eThe plugin's add_list() function processes the crafted input, triggering an unauthorized server-side request.\u003c/li\u003e\n\u003cli\u003eThe server acts as a proxy, sending a POST request to the Mailgun API authenticated with the compromised site's API key.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully interacts with the Mailgun API to create a malicious inbound routing rule.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers a password reset for a target administrator account on the WordPress site.\u003c/li\u003e\n\u003cli\u003eThe attacker intercepts the password reset email via the newly created Mailgun route, resulting in full account takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-78003 can result in complete site compromise. By intercepting administrative password resets, attackers can gain elevated privileges within the WordPress application. This vulnerability poses a critical threat to any organization relying on the Mailgun for WordPress plugin for email delivery, as the potential for unauthorized data access and persistence via malicious email routing is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Mailgun for WordPress plugin to a version beyond 2.2.0 immediately to apply the patch for CVE-2026-78003.\u003c/li\u003e\n\u003cli\u003eReview all configured Mailgun inbound routes for unauthorized entries, specifically looking for new forwarding rules that may have been created without administrative knowledge.\u003c/li\u003e\n\u003cli\u003eRotate the Mailgun API key associated with the WordPress site if there is any suspicion that the site was targeted by exploitation attempts.\u003c/li\u003e\n\u003cli\u003eAudit WordPress administrative activity logs for unexpected usage of the add_list() function or associated plugin administrative features by unauthorized sessions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-22T09:29:24Z","date_published":"2026-08-22T09:29:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mailgun-wordpress-ssrf/","summary":"An unauthenticated SSRF vulnerability in the Mailgun for WordPress plugin (\u003c= 2.2.0) allows attackers to perform unauthorized API requests and potentially intercept password reset emails, leading to account takeover.","title":"Unauthenticated SSRF in Mailgun for WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-mailgun-wordpress-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Mailgun for WordPress","version":"https://jsonfeed.org/version/1.1"}