Junglewise Threat Intelligence

CVE-2026-14919: ShopMonitor.io WordPress plugin authentication bypass via email rerouting

CVE-2026-14919 · Severity: info · CVSS 9.8 · Published 2026-07-31

Executive brief

The ShopMonitor.io plugin for WordPress, which is used to monitor e-commerce site performance, contains a critical security flaw in its email testing feature. An attacker can trick the plugin into redirecting all outgoing website emails to an address the attacker controls. This allows them to intercept sensitive communications, such as password reset links, and take full control of the website's administrator account.

Technical details

The ShopMonitor.io plugin fails to properly secure its email-rerouting test mode. The component relies on a 'trusted-source' check that can be bypassed by spoofing client-supplied request headers (such as X-Forwarded-For or similar). By satisfying this check, an unauthenticated remote attacker can enable email rerouting to an arbitrary address. This allows for the interception of sensitive transactional emails, most notably WordPress password-reset tokens, enabling full administrative account takeover. The vulnerability is fixed in version 1.2.0.

Affected products

  • ShopMonitor.io ShopMonitor.io before 1.2.0

Timeline

  • 2026-07-16: disclosed
  • 2026-07-31: advisory: NVD publication date
  • 2026-07-16: patched: Fixed in version 1.2.0

References