Junglewise Threat Intelligence

CVE-2026-78003: Mailgun for WordPress SSRF via path traversal

CVE-2026-78003 · Severity: critical · CVSS 9.8 · Published 2026-08-22

Executive brief

The Mailgun for WordPress plugin allows any attacker on the internet to make authenticated requests to Mailgun's API using the site's API credentials, without needing to log in. By crafting malicious requests, an attacker could intercept password reset emails or perform other actions on the site's behalf—potentially leading to administrator account takeover and complete site compromise.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) caused by insufficient input validation in the add_list() function. The plugin accepts user-controlled array keys from $_POST['addresses'], sanitizes them via sanitize_text_field(), but fails to validate them before passing them to the Mailgun API. This allows an unauthenticated attacker to make arbitrary authenticated POST requests to any Mailgun API endpoint using the WordPress site's stored API key. An attacker can exploit this without authentication to create inbound email-forwarding routes that intercept password reset emails, enabling account takeover. The vulnerability affects versions up to and including 2.2.0.

Affected products

  • Mailgun Mailgun for WordPress up to and including 2.2.0

Timeline

  • 2026-08-22: disclosed: CVE-2026-78003 published

References

Related threats