PatchSiren cyber security CVE debrief
CVE-2026-13156 MailerSend CVE debrief
The MailerSend WordPress plugin before 1.0.8 has a vulnerability that allows an attacker to trick a logged-in administrator into visiting a crafted page, resulting in the deletion of the plugin's SMTP configuration and deactivation of the plugin, breaking the site's email delivery. This vulnerability is related to the plugin's configuration-delete action, which does not perform a nonce check. As a result, an attacker can exploit this vulnerability to wipe the plugin's SMTP configuration and deactivate the plugin. The vulnerability has a medium defensive priority, and administrators of WordPress sites using the MailerSend plugin should verify that their plugin is up-to-date and consider reviewing user interactions with the plugin's configuration.
- Vendor
- MailerSend
- Product
- MailerSend WordPress plugin
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-20
Who should care
Administrators of WordPress sites using the MailerSend plugin should verify that their plugin is up-to-date and consider reviewing user interactions with the plugin's configuration. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on their organization's WordPress sites.
Technical summary
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action, allowing an attacker to trick a logged-in administrator into visiting a crafted page that wipes the plugin's SMTP configuration and deactivates the plugin. This vulnerability can be exploited by an attacker to delete the plugin's SMTP configuration and deactivate the plugin, breaking the site's email delivery. The plugin's configuration-delete action is vulnerable to a nonce check bypass, which allows an attacker to perform unauthorized actions on the plugin's configuration.
Defensive priority
Medium
Recommended defensive actions
- Verify that the MailerSend WordPress plugin is updated to version 1.0.8 or later.
- Review user interactions with the plugin's configuration to prevent unauthorized changes.
- Consider implementing additional security measures to prevent similar attacks.
- Monitor for suspicious activity related to the plugin's configuration-delete action.
- Perform a thorough review of the plugin's configuration and security settings.
- Consider implementing compensating controls to prevent exploitation of the vulnerability.
- Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved.
Evidence notes
The CVE record was published on 2026-07-20T07:16:35.687Z and has not been modified since then. The NVD entry is currently Received. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action, allowing an attacker to trick a logged-in administrator into visiting a crafted page that wipes the plugin's SMTP configuration and deactivates the plugin. Evidence of exploitation or affected deployments has not been confirmed.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-13156 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-13156
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-13156 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13156
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/595e653d-0904-43cf-8e61-d684599de11b/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.