cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches formailersend-official-smtp-integration mailersend-official-smtp-integration

Direction: ascending
Jul 23, 2026

MailerSend – Official SMTP Integration # CVE-2026-13156

CVE, Research URL

CVE-2026-13156

Date
Jul 20, 2026
Research Description
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.
Affected versions
max 1.0.8.
Status
vulnerable