THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-78003 (CRITICAL 9.8) — The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_PO

[NVD] CVE-2026-78003 (CRITICAL 9.8) — The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_PO

mednvdPublished 2026-08-22

CVE-2026-78003 CVSS: 9.8 CRITICAL Published: 2026-08-22T09:16:53.543

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through sanitize_text

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78003