CVE-2026-13156
The MailerSend WordPress plugin version 1.0.8 and earlier has a vulnerability that allows an attacker to trick an administrator into deleting the plugin's configuration and deactivating it, which would prevent the site from sending emails. This occurs because the plugin fails to verify a security token, known as a nonce, when the administrator attempts to delete the plugin's configuration. As a result, an attacker can create a malicious page that, when visited by an administrator, will delete the plugin's configuration and deactivate it. This would effectively break the site's email delivery functionality.
Based on public CVE data (MITRE/NVD).