Executive brief
The Zoho Mail plugin for WordPress, which allows websites to send emails via Zoho's secure API, is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. If an attacker successfully exploits this vulnerability, they could potentially modify the plugin's configuration, such as changing the sender's email address or API credentials. This could lead to unauthorized email delivery or disruption of the website's communication services.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Zohocorp Zoho Mail WordPress plugin before version 1.6.2. The vulnerability stems from insufficient validation of request origins on administrative actions within the plugin's configuration pages. An attacker can exploit this by inducing a logged-in administrator to visit a malicious website or click a crafted link, leading to unauthorized changes in plugin settings such as OAuth 2.0 credentials, 'From' email addresses, or mail server regions. The attack requires network connectivity and user interaction from an authenticated user. The issue is resolved in version 1.6.2.
Affected products
- Zohocorp Zoho Mail for WordPress before 1.6.2
Timeline
- 2026-05-26: advisory: CVE-2026-8174 published by NVD/ManageEngine