EUVD Vulnerability Catalog
EUVD-2026-64242
Severity: CRITICAL
Base Score: 9.8
CVSS Version: 3.1
Vulnerability Description
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through sanitize_text_field(). This makes it possible for unauthenticated attackers to make authenticated POST requests to any Mailgun API endpoint using the WordPress site's API key, including creating inbound email-forwarding routes that can intercept password reset emails, leading to administrator account takeover.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
mailgun
References & Advisory Links
- https://www.wordfence.com/threat-intel/vulnerabilities/id/110e888d-69fc-4682-b908-2b62288c5227?source=cve
- https://plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.php#L557
- https://plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.php#L259
- https://plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.php#L259
- https://plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.php#L323
- https://plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.php#L323
- https://plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.php#L331
- https://plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.php#L331
- https://plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.php#L557
- https://nvd.nist.gov/vuln/detail/CVE-2026-78003
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
Wordfence
EPSS Probability
0
Known Aliases
CVE-2026-78003
GHSA-jr9c-873v-948h
Published On
2026-08-22
Last Updated
2026-08-22