CVE Database /
CVE-2026-14834
CVE
CVE-2026-14834 — Mailgun for WordPress [mailgun] < 2.2.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-14834
|
Mailgun for WordPress [mailgun] < 2.2.1 |
Improper Access Control |
Unknown
|
< 2.2.1
|
2.2.1 |
2026-07-31 |
—
|
CVE-2026-14834
An unpatched version of the Mailgun for WordPress plugin, prior to 2.2.1, allows unauthorized access to its functionality through an unchecked AJAX action. This vulnerability enables malicious actors to add any email address to the site owner's mailing lists without proper authentication. The attacker can do this using the owner's stored API credentials.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings