CVE

CVE-2026-14834 — Mailgun for WordPress [mailgun] < 2.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-14834 Mailgun for WordPress [mailgun] < 2.2.1 Improper Access Control Unknown < 2.2.1 2.2.1 2026-07-31

CVE-2026-14834

An unpatched version of the Mailgun for WordPress plugin, prior to 2.2.1, allows unauthorized access to its functionality through an unchecked AJAX action. This vulnerability enables malicious actors to add any email address to the site owner's mailing lists without proper authentication. The attacker can do this using the owner's stored API credentials.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.