Mailgun For Wordpress

WordPress plugin · mailgun-for-wordpress · WordPress.org ↗
1
Critical
0
High
2
Known total
1
Unfixed
Running Mailgun For Wordpress on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
CRITICAL
CVSS 9.8
Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys
CVE.org
<=2.2.0 unfixed CVE-2026-78003 Aug 22, 2026
MEDIUM
CVSS 6.5
Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX
CVE.org
>=0, <2.2.1 v2.2.1 CVE-2026-14834 Jul 31, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.