THREAT OPS › Threat News › [NVD] CVE-2026-78003 (CRITICAL 9.8) — The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_PO
[NVD] CVE-2026-78003 (CRITICAL 9.8) — The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_PO
CVE-2026-78003 CVSS: 9.8 CRITICAL Published: 2026-08-22T09:16:53.543
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through sanitize_text
Indicators of compromise
- CVE-2026-78003cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78003