cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches formailgun mailgun

Direction: ascending
Aug 01, 2026

Mailgun for WordPress # CVE-2026-14834

CVE, Research URL

CVE-2026-14834

Application

Mailgun for WordPress

Date
Jul 31, 2026
Research Description
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials.
Affected versions
max 2.2.1.
Status
vulnerable