CVE-2026-14834
Received Received - Intake

Unauthenticated Email Subscription in Mailgun for WordPress Plugin

Vulnerability report for CVE-2026-14834, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: WPScan

Description

The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mailgun mailgun_for_wordpress to 2.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Mailgun for WordPress plugin before version 2.2.1 has a flaw where it fails to verify user permissions or use security tokens for an AJAX action that adds subscribers to mailing lists. This allows unauthenticated attackers to add any email address to the site owner's mailing lists using the owner's stored API credentials.

Detection Guidance

Check if the Mailgun for WordPress plugin version is below 2.2.1. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files in the /wp-content/plugins/ directory for version information.

Impact Analysis

If you use this plugin, attackers could add unauthorized email addresses to your mailing lists, potentially spamming subscribers or misusing your API credentials. This could damage your reputation, waste resources, and lead to account suspension if the service detects abuse.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR if personal data is processed without consent, as unauthorized additions to mailing lists may violate data protection requirements. For HIPAA, if the plugin handles protected health information, unauthorized access could breach confidentiality rules.

Mitigation Strategies

Update the Mailgun for WordPress plugin to version 2.2.1 or later immediately. Remove any unauthorized subscribers from your mailing lists and review API credentials for misuse.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14834. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart