The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-31 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-14834
Mitre link : CVE-2026-14834
CVE.ORG link : CVE-2026-14834
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
