PLUGIN SECURITY
Is Mailgun safe?
Easily send email from your WordPress site through Mailgun using the HTTP API or SMTP.
What this plugin does
- Slug:
mailgun - Author: Mailgun
- 80000+ active installs
- 76/100 rating (49 reviews on wordpress.org)
- 2841761 all-time downloads
- On WordPress.org since 2012-11-21
apihttpmailmailgunsmtp
Maintenance status
- Latest known version: 2.2.2
- Last updated: 2026-07-17 12:06pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
2 known CVEs on file for Mailgun. Reported between 2026 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-14834 | Mailgun for WordPress [mailgun] < 2.2.1 | Improper Access Control | Unknown | < 2.2.1 | 2.2.1 | 2026-07-31 | ✓ fixed in latest |
| CVE-2026-78003 | Mailgun for WordPress [mailgun] < 2.2.1 | Server-Side Request Forgery (SSRF) | Critical 9.8 | < 2.2.1 | 2.2.1 | 2026-07-13 | ✓ fixed in latest |
How to fix it
Keep Mailgun updated — 2.2.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WP Consent API — 200000+ active installs — 100/100 (2) — max PHP 8.4
- Disable REST API — 80000+ active installs — 96/100 (38)
- Make Connector — 80000+ active installs — 54/100 (25) — max PHP 8.4
- Disable WP REST API — 30000+ active installs — 96/100 (36)
- WP REST Cache — 10000+ active installs — 98/100 (42)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.